SSCP Systems and Application Security Practice Question
A security administrator is building a Security Information and Event Management (SIEM) correlation rule to detect a specific attack pattern on a Linux web server. The rule must identify attempts where an attacker sends a single malicious HTTP request that causes the server to execute an arbitrary operating system command. Which of the following event sources would provide the most reliable and immediate evidence for this rule?
⚠ Common exam trap
The trap here is assuming that web server access logs alone can confirm command execution, when they only show the request, not the resulting process activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Linux auditd logs configured to monitor execve system calls
Detecting arbitrary command execution requires visibility into process creation on the host. Linux auditd can monitor the execve system call, capturing the exact command line and parent process for every new program. This gives the SIEM immediate, high-fidelity evidence of the attack, unlike network flow or web access logs that lack process-level context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apache access logs with the Combined Log Format enabled
Why it's wrong here
Apache access logs record the HTTP request line, status code, and user agent but do not show operating system commands executed by the web server. While they may show the malicious request, they cannot confirm command execution. They are useful for identifying the initial vector but not for directly detecting the command execution itself, making them less reliable for this specific rule.
- ✗
NetFlow records exported from the network router
Why it's wrong here
NetFlow provides metadata about network flows, such as source/destination IP, ports, and byte counts. It does not inspect payloads or process execution. A command execution attack may not generate a distinct network flow if the command output is sent back over the same HTTP connection. Therefore, NetFlow cannot reliably indicate that a command was executed on the server.
- ✓
Linux auditd logs configured to monitor execve system calls
Why this is correct
auditd can monitor the execve system call, which is invoked whenever a new process is executed. By configuring a rule to watch execve, the SIEM will receive an event containing the full command line and the parent process. This directly detects the arbitrary command execution caused by the malicious HTTP request, providing immediate and reliable evidence.
- ✗
Syslog messages from the SSH daemon
Why it's wrong here
SSH daemon logs record authentication attempts and session establishment, not commands executed by the web server process. If the attacker did not use SSH, these logs would be irrelevant. Even if SSH was used, they would not capture commands spawned by the web server. Thus, they are not the best source for detecting this specific attack.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.