ISC2 CC Security Operations Practice Question
A security team is implementing a Security Information and Event Management (SIEM) system. Which TWO log sources are most critical for detecting unauthorized access attempts on a Linux server? (Choose two.)
⚠ Common exam trap
The trap here is assuming that syslog contains all security events, but authentication logs are specifically separated into auth.log or secure depending on the distribution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/var/log/secure
On Linux systems, authentication events are logged in /var/log/auth.log (Debian-based) or /var/log/secure (Red Hat-based). These files record failed and successful login attempts, sudo usage, and SSH access, making them critical for detecting unauthorized access. Other logs like syslog, kern.log, or dpkg.log serve different purposes and are less directly relevant to access attempts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/var/log/kern.log
Why it's wrong here
The /var/log/kern.log file contains kernel messages, such as hardware drivers and system startup information. It may log some security events like firewall drops, but it is not the primary source for authentication attempts. Unauthorized access attempts are better detected through auth.log or secure. Kern.log is more relevant for system diagnostics.
- ✗
/var/log/syslog
Why it's wrong here
The /var/log/syslog file contains general system messages, including kernel and service logs. While it may contain some security-relevant information, it is not specifically focused on authentication events. Unauthorized access attempts are more directly captured in auth.log. Syslog is useful for troubleshooting but less critical for detecting access attempts.
- ✓
/var/log/secure
Why this is correct
On Red Hat-based Linux distributions, /var/log/secure serves the same purpose as /var/log/auth.log on Debian-based systems. It records authentication and security-related events, including failed logins and sudo usage. Monitoring this file is critical for detecting unauthorized access attempts on those systems. It is a primary source for security auditing.
- ✓
/var/log/auth.log
Why this is correct
The /var/log/auth.log file on Linux systems records authentication events, including successful and failed login attempts, sudo commands, and SSH access. Monitoring this log is essential for detecting unauthorized access attempts, such as brute-force attacks or privilege escalation. It provides direct evidence of who attempted to access the system and whether they succeeded.
- ✗
/var/log/dpkg.log
Why it's wrong here
The /var/log/dpkg.log file records package installation and removal events. It is not related to authentication or access attempts. While it can help track software changes, it does not provide information about login attempts or privilege escalation. Therefore, it is not a critical log source for detecting unauthorized access.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Design
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
SSH
SSH (Secure Shell) is a cryptographic network protocol that provides secure, encrypted communication and remote administration between two devices over an unsecured network.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.