← Linux & macOS Forensics — Logs, Persistence, and Artifact Locations

Module Quiz

10 questions · Pass at 80%

Question 1 of 10

An attacker deleted /var/log/auth.log on a Debian Linux server immediately after gaining SSH access. The server uses persistent journald logging. Which authentication evidence sources remain intact?