Answered step by step
Verified Expert Solution
Question
1 Approved Answer
Install auditd using the apt package manager. Verify the auditd service using the systemctl command. Configure the / etc / audit / auditd . conf
Install auditd using the apt package manager.
Verify the auditd service using the systemctl command.
Configure the etcauditauditdconf file with the following parameters using sudo:
Log file location is varlogauditauditlog
Number of retained logs is
Maximum log file size is
Check to make sure there are no existing rules.
Create a rule that will monitor etcpasswd and etcshadow for any changes.
Restart the auditd daemon.
Check to verify the new rules have taken place.
Add a new rule to audit the usr directory.
Verify the new rule by listing auditcl rules.
Perform a search in the authentication report for user authentication attempts.
Make sure to disable your current sudo access with sudo k This option revokes your current sudo session, requiring you to have to enter your password on your next sudo command.
Perform a sudo su three times using the wrong password, then run the same report again.
Create a new user, criminal, then perform a search for account modifications.
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started