Keep privileged Linux identity changes visible

A hands-on SY0-701 lab. You produce the real artefact and 9 automated checks verify it behaves the way the exam expects.

Try this labAll SY0-701 practice

Certification
SY0-701
Format
Artifact workspace
Difficulty
medium
Estimated time
12 min
Automated checks
9

The brief

Repair identity.rules. Clear the previous rules first, keep backlog 8192 and failure mode 1, then use 64-bit always/exit syscall rules to monitor /etc/passwd, /etc/shadow, /etc/group, /etc/sudoers, and the /etc/sudoers.d/ directory. Record write and attribute changes only, put every rule under identity_changes, and finish with -e 2 so the loaded rules remain locked until reboot.

Part of SY0-701 preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.