Keep privileged Linux identity changes visible
A hands-on SY0-701 lab. You produce the real artefact and 9 automated checks verify it behaves the way the exam expects.
Try this labAll SY0-701 practice
- Certification
- SY0-701
- Format
- Artifact workspace
- Difficulty
- medium
- Estimated time
- 12 min
- Automated checks
- 9
The brief
Repair identity.rules. Clear the previous rules first, keep backlog 8192 and failure mode 1, then use 64-bit always/exit syscall rules to monitor /etc/passwd, /etc/shadow, /etc/group, /etc/sudoers, and the /etc/sudoers.d/ directory. Record write and attribute changes only, put every rule under identity_changes, and finish with -e 2 so the loaded rules remain locked until reboot.
Part of SY0-701 preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.