CompTIA Linux+ (XK0-006)SecurityMedium
After hardening a server, an administrator initializes a file integrity baseline using AIDE by running aide --init and copying the resulting database into place. Which command should be scheduled via cron to routinely detect unauthorized changes against that baseline?
- Aaide --check
- Baide --init
- Caide --update
- Daide --config-check
Show answer & explanationAnswer & explanation
Correct answer: A. aide --check
aide --check compares the current filesystem state against the stored baseline database (/var/lib/aide/aide.db.gz) and reports any additions, deletions, or modifications, making it the correct command for ongoing integrity monitoring.
Why the other options are wrong
- B. aide --init creates the initial baseline database and would overwrite it if rerun, not used for ongoing checks.
- C. aide --update generates a new database reflecting current state, typically used after legitimate changes, not for detection.
- D. aide --config-check is not a valid AIDE operational mode for integrity checking.
AIDE File Integrity Checking
AIDE (Advanced Intrusion Detection Environment) creates a cryptographic baseline of file attributes and later compares the filesystem against it to detect unauthorized changes.
- aide --init builds initial database as aide.db.new.gz
- Database must be moved/renamed to aide.db.gz to activate it
- aide --check compares against active database
- Configuration lives in /etc/aide/aide.conf
Memory trick: Init sets the photo, Check compares the room to the photo.