Skip to content
XK0-006
Security
hard
Question 1 of 18

An administrator suspects unauthorized modifications to /etc/passwd and needs to query the audit daemon logs for all recorded events related to that file. Which command should they use?

Agrep /etc/passwd /var/log/secure
Bausearch -f /etc/passwd
Cauditctl -l /etc/passwd
Djournalctl -f /etc/passwd

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion