EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy
A security analyst is investigating a suspected breach on a Linux server. They notice that the `/var/log/auth.log` file, which normally records authentication attempts, has been completely emptied. What is the most likely reason for this observation?
- AAn attacker cleared the logs to hide their activities.
- BA legitimate log rotation process occurred at an unusual time.
- CA system update process accidentally deleted the log file.
- DThe system has been rebooted, clearing volatile logs.
Show answer & explanationAnswer & explanation
Correct answer: A. An attacker cleared the logs to hide their activities.
Completely emptying critical log files like `/var/log/auth.log` is a classic tactic used by attackers to remove evidence of their presence and actions on a compromised system, falling under the 'Clearing Logs' phase.
Why the other options are wrong
- B. Log rotation typically archives and compresses logs, not completely empties them without a new file being created, and usually follows a schedule.
- C. System updates rarely delete critical log files without prior archiving or specific configuration.
- D. `/var/log/auth.log` is persistent across reboots; only volatile memory logs are cleared.
Clearing Logs
Clearing logs is a post-exploitation activity where an attacker attempts to remove or modify system and application log files to hide their presence and activities on a compromised system.
- Aims to evade detection by security monitoring tools and forensic analysis.
- Can involve deleting, truncating, or modifying log entries.
- Is a common tactic in the 'Clearing Tracks' phase of an attack.
Memory trick: No trace left behind, the ghost was here!