Courseiva
Security Operations →mediumMultiple Select

ISC2 CC Security Operations Practice Question

A security team is implementing a Security Information and Event Management (SIEM) system. Which TWO log sources are most critical for detecting unauthorized access attempts on a Linux server? (Choose two.)

⚠ Common exam trap

The trap here is assuming that syslog contains all security events, but authentication logs are specifically separated into auth.log or secure depending on the distribution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/var/log/secure

On Linux systems, authentication events are logged in /var/log/auth.log (Debian-based) or /var/log/secure (Red Hat-based). These files record failed and successful login attempts, sudo usage, and SSH access, making them critical for detecting unauthorized access. Other logs like syslog, kern.log, or dpkg.log serve different purposes and are less directly relevant to access attempts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    /var/log/kern.log

    Why it's wrong here

    The /var/log/kern.log file contains kernel messages, such as hardware drivers and system startup information. It may log some security events like firewall drops, but it is not the primary source for authentication attempts. Unauthorized access attempts are better detected through auth.log or secure. Kern.log is more relevant for system diagnostics.

  • ✗

    /var/log/syslog

    Why it's wrong here

    The /var/log/syslog file contains general system messages, including kernel and service logs. While it may contain some security-relevant information, it is not specifically focused on authentication events. Unauthorized access attempts are more directly captured in auth.log. Syslog is useful for troubleshooting but less critical for detecting access attempts.

  • ✓

    /var/log/secure

    Why this is correct

    On Red Hat-based Linux distributions, /var/log/secure serves the same purpose as /var/log/auth.log on Debian-based systems. It records authentication and security-related events, including failed logins and sudo usage. Monitoring this file is critical for detecting unauthorized access attempts on those systems. It is a primary source for security auditing.

  • ✓

    /var/log/auth.log

    Why this is correct

    The /var/log/auth.log file on Linux systems records authentication events, including successful and failed login attempts, sudo commands, and SSH access. Monitoring this log is essential for detecting unauthorized access attempts, such as brute-force attacks or privilege escalation. It provides direct evidence of who attempted to access the system and whether they succeeded.

  • ✗

    /var/log/dpkg.log

    Why it's wrong here

    The /var/log/dpkg.log file records package installation and removal events. It is not related to authentication or access attempts. While it can help track software changes, it does not provide information about login attempts or privilege escalation. Therefore, it is not a critical log source for detecting unauthorized access.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.