CompTIA Linux+ (XK0-006)SecurityMedium

After hardening a server, an administrator initializes a file integrity baseline using AIDE by running aide --init and copying the resulting database into place. Which command should be scheduled via cron to routinely detect unauthorized changes against that baseline?

  1. Aaide --check
  2. Baide --init
  3. Caide --update
  4. Daide --config-check
Show answer & explanation

Correct answer: A. aide --check

aide --check compares the current filesystem state against the stored baseline database (/var/lib/aide/aide.db.gz) and reports any additions, deletions, or modifications, making it the correct command for ongoing integrity monitoring.

Why the other options are wrong

  • B. aide --init creates the initial baseline database and would overwrite it if rerun, not used for ongoing checks.
  • C. aide --update generates a new database reflecting current state, typically used after legitimate changes, not for detection.
  • D. aide --config-check is not a valid AIDE operational mode for integrity checking.

AIDE File Integrity Checking

AIDE (Advanced Intrusion Detection Environment) creates a cryptographic baseline of file attributes and later compares the filesystem against it to detect unauthorized changes.

  • aide --init builds initial database as aide.db.new.gz
  • Database must be moved/renamed to aide.db.gz to activate it
  • aide --check compares against active database
  • Configuration lives in /etc/aide/aide.conf

Memory trick: Init sets the photo, Check compares the room to the photo.

More Security questions