GSEC Linux Fundamentals Practice Question
An administrator is reviewing system logs to identify potential unauthorized access attempts. Which TWO commands are commonly used to view the last few lines of a log file in real-time?
⚠ Common exam trap
Candidates often choose static commands like 'cat' or 'more', which do not update in real-time, failing to realize that active incident response requires continuous monitoring of log file growth.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
tail -f /var/log/auth.log
Monitoring logs in real-time is a fundamental skill for GSEC professionals to detect ongoing attacks or system errors. The 'tail -f' command is the standard utility for following a file's growth. Alternatively, 'less +F' offers a more robust interface that allows the admin to toggle between real-time monitoring and static analysis, providing better flexibility when investigating complex log entries during an active incident response scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
tail -f /var/log/auth.log
Why this is correct
The '-f' flag tells the tail utility to follow the file, meaning it will continuously display new lines as they are appended to the log. This is the industry-standard method for live log monitoring and immediate detection of authentication failures, such as repeated SSH login attempts or brute-force attacks.
- ✗
head -n 20 /var/log/auth.log
Why it's wrong here
The head command displays the beginning of a file. It is not suitable for monitoring real-time logs because it does not update as new lines are written. Using head would only show historical, static data from the start of the file, failing to capture ongoing security events.
- ✓
less +F /var/log/auth.log
Why this is correct
The '+F' option in the less pager puts the utility into a mode similar to 'tail -f', monitoring for new additions. This is highly effective because it allows the user to press Ctrl+C to pause the stream, search through history, and then resume monitoring without restarting the command.
- ✗
cat /var/log/auth.log | grep -v 'accepted'
Why it's wrong here
The cat command outputs the entire file content at once and terminates. It does not provide real-time updates. While piping to grep is useful for filtering text, it provides a static snapshot of the file's contents at the moment the command was executed, missing any subsequent log entries.
- ✗
more /var/log/auth.log
Why it's wrong here
The more command is a legacy pager that displays file contents page-by-page. It lacks the functionality to follow a file as it grows. Once the end of the file is reached, it exits, making it unsuitable for the active observation required during security troubleshooting or real-time log analysis.
About these practice questions
One of 351 original GSEC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.