Courseiva
Linux Fundamentals →mediumMultiple Choice

GSEC Linux Fundamentals Practice Question

An administrator is reviewing system logs to identify potential unauthorized access attempts. Which TWO commands are commonly used to view the last few lines of a log file in real-time?

⚠ Common exam trap

Candidates often choose static commands like 'cat' or 'more', which do not update in real-time, failing to realize that active incident response requires continuous monitoring of log file growth.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

tail -f /var/log/auth.log

Monitoring logs in real-time is a fundamental skill for GSEC professionals to detect ongoing attacks or system errors. The 'tail -f' command is the standard utility for following a file's growth. Alternatively, 'less +F' offers a more robust interface that allows the admin to toggle between real-time monitoring and static analysis, providing better flexibility when investigating complex log entries during an active incident response scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    tail -f /var/log/auth.log

    Why this is correct

    The '-f' flag tells the tail utility to follow the file, meaning it will continuously display new lines as they are appended to the log. This is the industry-standard method for live log monitoring and immediate detection of authentication failures, such as repeated SSH login attempts or brute-force attacks.

  • ✗

    head -n 20 /var/log/auth.log

    Why it's wrong here

    The head command displays the beginning of a file. It is not suitable for monitoring real-time logs because it does not update as new lines are written. Using head would only show historical, static data from the start of the file, failing to capture ongoing security events.

  • ✓

    less +F /var/log/auth.log

    Why this is correct

    The '+F' option in the less pager puts the utility into a mode similar to 'tail -f', monitoring for new additions. This is highly effective because it allows the user to press Ctrl+C to pause the stream, search through history, and then resume monitoring without restarting the command.

  • ✗

    cat /var/log/auth.log | grep -v 'accepted'

    Why it's wrong here

    The cat command outputs the entire file content at once and terminates. It does not provide real-time updates. While piping to grep is useful for filtering text, it provides a static snapshot of the file's contents at the moment the command was executed, missing any subsequent log entries.

  • ✗

    more /var/log/auth.log

    Why it's wrong here

    The more command is a legacy pager that displays file contents page-by-page. It lacks the functionality to follow a file as it grows. Once the end of the file is reached, it exits, making it unsuitable for the active observation required during security troubleshooting or real-time log analysis.

About these practice questions

One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.