Problem Statement
What is the purpose of Linux auditd in hardening and operations?
Explanation
The Linux Audit system (auditd plus the kernel audit module) captures policy-relevant events like file access, authentication, and admin actions. It helps investigations and compliance by producing a tamper-evident trail. Sources: Red Hat and SUSE security guides and modern auditd explanations.
Code Solution
SolutionRead Only
Example rule: auditctl -w /etc/passwd -p wa -k identity_changes
