PrepAway - Latest Free Exam Questions & Answers

Which log files should be trusted to track an intrusion after a remote attacker with root privileges compromis

Which log files should be trusted to track an intrusion after a remote attacker with root privileges compromises a system on a local area network (LAN)?

PrepAway - Latest Free Exam Questions & Answers

A.
the /var/adm/sulog file

B.
the /var/adm/wtmpx file with read-only permissions

C.
the syslog /var/adm/messages file with read-only permissions

D.
the forwarded syslog log files on a remote system with console access only


Leave a Reply