CompTIA SecurityX (CAS-005)Security OperationsMedium
A forensic investigator is analyzing a compromised Linux server. They find evidence of an attacker modifying the `/etc/passwd` file and creating a new user with root privileges. To determine the exact command used by the attacker to modify the file and create the user, which Linux audit subsystem would provide the most precise and detailed information?
- ASyslog
- BDmesg
- CAuditd
- DJournald
Show answer & explanationAnswer & explanation
Correct answer: C. Auditd
Auditd (Linux Audit System) is specifically designed to provide detailed, configurable logging of system calls and file access, including who accessed what, when, and the exact commands executed. This makes it ideal for forensic investigations requiring high granularity on file modifications and user creation events, especially for critical files like `/etc/passwd`.
Why the other options are wrong
- A. Syslog is a general-purpose logging system but typically lacks the granularity to show the exact command used for file modification by a specific user.
- B. Dmesg logs kernel ring buffer messages, primarily for hardware and kernel events, not user-level file modifications or command execution.
- D. Journald is a systemd logging service, which aggregates logs, but auditd provides more forensic-level detail for file access and command execution.
Linux Auditd
The Linux Audit System (auditd) provides a way to track security-relevant information on a system. It can log system calls, file access, process execution, and network activity with high granularity, making it invaluable for forensic analysis and compliance.
- Tracks system calls and file access.
- Records user, process, and command details.
- Crucial for forensic investigations on Linux.
Memory trick: Auditd Logs the Actions, Syslog Logs the Status.