CompTIA CySA+ (CS0-003)Incident Response and ManagementHard

A security analyst is investigating a suspected security incident on a Linux server. The primary goal is to determine if unauthorized commands were executed and by which user accounts. The analyst has access to the server's command history files and system logs. Which of the following log files or commands would provide the MOST direct evidence of commands executed by specific users, including their timestamps?

  1. A/var/log/auth.log
  2. B/var/log/syslog
  3. Cjournalctl
  4. D~/.bash_history
Show answer & explanation

Correct answer: D. ~/.bash_history

The ~/.bash_history file (or equivalent for other shells like ~/.zsh_history) directly records commands executed by a specific user within their shell session. While other logs provide system-level events, the shell history is paramount for user-specific command execution. Assuming the attacker did not clear it, it provides a direct record.

Why the other options are wrong

  • A. /var/log/auth.log records authentication attempts and privilege escalations, not executed commands.
  • B. /var/log/syslog contains general system messages, not user-specific command history.
  • C. journalctl is a utility to query and display messages from the systemd journal, which aggregates various logs but doesn't directly store user command history by default.

Linux User Command History

Files maintained by command-line shells (e.g., Bash, Zsh) that record commands executed by individual users, providing a direct audit trail of user activity.

  • Typically stored in a hidden file in the user's home directory (e.g., ~/.bash_history).
  • Can be modified or cleared by attackers.
  • Crucial for identifying unauthorized user actions.

Memory trick: Bash History Shows User's True Intent

More Incident Response and Management questions