Courseiva
Manage containers →mediumMatching

EX200 Manage containers Practice Question

Match each log file to its typical content.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

General system log (most non-critical messages)

Authentication and security events

Audit records from auditd

Cron job execution logs

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

/var/log/messages: General system messages and events

These log files are commonly monitored by sysadmins. Correct matches: /var/log/messages for general messages, /var/log/secure for authentication, /var/log/maillog for mail, /var/log/cron for cron jobs. Common confusions involve swapping secure and maillog.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    /var/log/messages: General system messages and events

    Why this is correct

    On Red Hat Enterprise Linux and derivatives, /var/log/messages is the default destination for general system events written by rsyslogd. It captures kernel notifications, service start/stop messages, and daemon-level informational logs, but authentication entries are deliberately routed to /var/log/secure. This file is the first stop when troubleshooting generic system issues, while auth records are saved separately for security auditing.

  • ✓

    /var/log/secure: Authentication and security-related messages

    Why this is correct

    The /var/log/secure log is specifically configured to record authentication and security-related events, such as SSH login attempts, su failures, sudo invocations, and PAM session activity. On Red Hat-based systems, the authpriv facility is directed to this file, making it the primary source for investigating unauthorized access or privilege escalation. Unlike /var/log/messages, it excludes routine kernel and service notices to keep security-sensitive data isolated.

  • ✓

    /var/log/maillog: Mail server logs

    Why this is correct

    The /var/log/maillog is the system's mail transfer agent log, capturing all inbound and outbound email traffic processed by services like sendmail, postfix, and dovecot. It contains queue IDs, sender/recipient addresses, delivery status, and relay details, which are essential for diagnosing mail delivery failures or spam-relay issues. On other distributions this file may be named /var/log/mail.log, but Red Hat consistently uses maillog.

  • ✓

    /var/log/cron: Cron job execution logs

    Why this is correct

    The /var/log/cron log is written by cron itself and records every job execution, including timestamps, command paths, and the invoking user's account. If a cron job fails or produces unexpected output, this file shows whether the job started, what command was attempted, and any stderr or stdout that was logged. However, to debug the actual job logic, administrators must also check the cron configuration in /etc/crontab and /etc/cron.d, because this log only shows execution metadata.

  • ✗

    /var/log/messages: Authentication and security-related messages

    Why it's wrong here

    The claim that /var/log/messages holds authentication and security-related messages is incorrect because Red Hat's rsyslog configuration separates the authpriv facility and directs it to /var/log/secure. While a subset of kernel-level security events may appear in messages, login attempts, sudo commands, and PAM results are almost exclusively written to secure. Treating /var/log/messages as the auth log could lead to missing critical evidence during a security investigation.

  • ✗

    /var/log/secure: Mail server logs

    Why it's wrong here

    The claim that /var/log/secure contains mail server logs is a mix-up of Red Hat's log routing; mail events are handled by the mail facility and written to /var/log/maillog, not to secure. The /var/log/secure file is reserved for authentication and privilege authorization records, including SSH and sudo. Examining secure for mail queues or delivery errors would yield nothing relevant, whereas maillog contains the full mail transaction trail.

About these practice questions

Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.