← Linux & macOS Forensics — Logs, Persistence, and Artifact Locations
Module Quiz
10 questions · Pass at 80%
Question 1 of 10
An attacker deleted /var/log/auth.log on a Debian Linux server immediately after gaining SSH access. The server uses persistent journald logging. Which authentication evidence sources remain intact?