Q: After a security breach, you need to audit all file access and command execution on a Linux server. What kernel-level auditing framework is available, and how do you set it up?
The Linux Audit Framework (auditd) is a kernel-level subsystem that records system calls, file access, and user actions for security comp...
#Linux #Linux / SRE — Scenario-Based Interview Questions #L3 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""In an interview, I explain my systematic Linux troubleshooting methodology using Brendan Gregg's USE method. The interviewer is testing: Linux Audit Framework (auditd), security forensics.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
The Linux Audit Framework (auditd) is a kernel-level subsystem that records system calls, file access, and user actions for security compliance and forensics.
- Install and enable:
- Add audit rules in
/etc/audit/rules.d/audit.rules: - Load rules:
augenrules --load
2️⃣
Remediation & Permanent Safeguards
Setup: The audit log is stored in /var/log/audit/audit.log and can be forwarded to a SIEM (like Splunk or ELK) for centralized analysis. For compliance standards like PCI-DSS or SOC2, auditd is often a mandatory requirement.
yum install audit
systemctl enable --now auditd
- Search audit logs:
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Install and enable:."
⚡ 60-Second Elevator Pitch Talking Points
- Install and enable:
- Add audit rules in /etc/audit/rules.d/audit.rules:
- Load rules: augenrules --load
Advertisement