EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy

A security analyst is investigating a suspected breach on a Linux server. They notice that the `/var/log/auth.log` file, which normally records authentication attempts, has been completely emptied. What is the most likely reason for this observation?

  1. AAn attacker cleared the logs to hide their activities.
  2. BA legitimate log rotation process occurred at an unusual time.
  3. CA system update process accidentally deleted the log file.
  4. DThe system has been rebooted, clearing volatile logs.
Show answer & explanation

Correct answer: A. An attacker cleared the logs to hide their activities.

Completely emptying critical log files like `/var/log/auth.log` is a classic tactic used by attackers to remove evidence of their presence and actions on a compromised system, falling under the 'Clearing Logs' phase.

Why the other options are wrong

  • B. Log rotation typically archives and compresses logs, not completely empties them without a new file being created, and usually follows a schedule.
  • C. System updates rarely delete critical log files without prior archiving or specific configuration.
  • D. `/var/log/auth.log` is persistent across reboots; only volatile memory logs are cleared.

Clearing Logs

Clearing logs is a post-exploitation activity where an attacker attempts to remove or modify system and application log files to hide their presence and activities on a compromised system.

  • Aims to evade detection by security monitoring tools and forensic analysis.
  • Can involve deleting, truncating, or modifying log entries.
  • Is a common tactic in the 'Clearing Tracks' phase of an attack.

Memory trick: No trace left behind, the ghost was here!

More System Hacking Phases and Attack Techniques questions