Drag a concept onto its matching description — or click a concept then click the description.
General system log (most non-critical messages)
Authentication and security events
Audit records from auditd
Cron job execution logs
Match each log file to its typical content.
Drag a concept onto its matching description — or click a concept then click the description.
General system log (most non-critical messages)
Authentication and security events
Audit records from auditd
Cron job execution logs
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
/var/log/messages: General system messages and events
These log files are commonly monitored by sysadmins. Correct matches: /var/log/messages for general messages, /var/log/secure for authentication, /var/log/maillog for mail, /var/log/cron for cron jobs. Common confusions involve swapping secure and maillog.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
/var/log/messages: General system messages and events
Why this is correct
On Red Hat Enterprise Linux and derivatives, /var/log/messages is the default destination for general system events written by rsyslogd. It captures kernel notifications, service start/stop messages, and daemon-level informational logs, but authentication entries are deliberately routed to /var/log/secure. This file is the first stop when troubleshooting generic system issues, while auth records are saved separately for security auditing.
/var/log/secure: Authentication and security-related messages
Why this is correct
The /var/log/secure log is specifically configured to record authentication and security-related events, such as SSH login attempts, su failures, sudo invocations, and PAM session activity. On Red Hat-based systems, the authpriv facility is directed to this file, making it the primary source for investigating unauthorized access or privilege escalation. Unlike /var/log/messages, it excludes routine kernel and service notices to keep security-sensitive data isolated.
/var/log/maillog: Mail server logs
Why this is correct
The /var/log/maillog is the system's mail transfer agent log, capturing all inbound and outbound email traffic processed by services like sendmail, postfix, and dovecot. It contains queue IDs, sender/recipient addresses, delivery status, and relay details, which are essential for diagnosing mail delivery failures or spam-relay issues. On other distributions this file may be named /var/log/mail.log, but Red Hat consistently uses maillog.
/var/log/cron: Cron job execution logs
Why this is correct
The /var/log/cron log is written by cron itself and records every job execution, including timestamps, command paths, and the invoking user's account. If a cron job fails or produces unexpected output, this file shows whether the job started, what command was attempted, and any stderr or stdout that was logged. However, to debug the actual job logic, administrators must also check the cron configuration in /etc/crontab and /etc/cron.d, because this log only shows execution metadata.
/var/log/messages: Authentication and security-related messages
Why it's wrong here
The claim that /var/log/messages holds authentication and security-related messages is incorrect because Red Hat's rsyslog configuration separates the authpriv facility and directs it to /var/log/secure. While a subset of kernel-level security events may appear in messages, login attempts, sudo commands, and PAM results are almost exclusively written to secure. Treating /var/log/messages as the auth log could lead to missing critical evidence during a security investigation.
/var/log/secure: Mail server logs
Why it's wrong here
The claim that /var/log/secure contains mail server logs is a mix-up of Red Hat's log routing; mail events are handled by the mail facility and written to /var/log/maillog, not to secure. The /var/log/secure file is reserved for authentication and privilege authorization records, including SSH and sudo. Examining secure for mail queues or delivery errors would yield nothing relevant, whereas maillog contains the full mail transaction trail.
Go deeper
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.