CompTIA Security+ (SY0-701)Security OperationsMedium
A compliance team requires immediate alerts whenever critical operating system files, such as boot configuration files or system binaries, are modified without an approved change ticket. Which control should be implemented to meet this requirement?
- AData loss prevention (DLP)
- BFile integrity monitoring (FIM)
- CUser and entity behavior analytics (UEBA)
- DNetwork access control (NAC)
Show answer & explanationAnswer & explanation
Correct answer: B. File integrity monitoring (FIM)
FIM tools calculate and store cryptographic hashes of critical files and alert when a file's hash changes, indicating unauthorized modification. DLP focuses on data exfiltration, NAC controls network admission, and UEBA focuses on behavioral anomalies rather than file content changes.
Why the other options are wrong
- A. DLP prevents sensitive data from leaving the organization, not file tampering detection.
- C. UEBA baselines user/entity behavior patterns, not specific file hashes.
- D. NAC controls which devices can join the network, unrelated to file changes.
File Integrity Monitoring (FIM)
A security control that monitors and alerts on unauthorized changes to critical system or configuration files by comparing current file hashes to a known-good baseline.
- Uses cryptographic hashing to detect changes
- Commonly monitors OS binaries, config files, and logs
- Helps detect rootkits, tampering, and unauthorized changes
Memory trick: FIM fingerprints files so any tampering shows up like a smudge.