Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium
An organization is deploying a new host-based intrusion detection system (HIDS) across its Windows server environment. The security team wants to ensure the HIDS is configured to detect unauthorized modifications to critical system files and registry keys, which are common tactics for persistence and privilege escalation. Which HIDS capability is primarily responsible for monitoring and alerting on these types of changes?
- ANetwork anomaly detection
- BBehavioral analysis engine
- CFile integrity monitoring (FIM)
- DSignature-based malware detection
Show answer & explanationAnswer & explanation
Correct answer: C. File integrity monitoring (FIM)
File integrity monitoring (FIM) is a core HIDS capability that continuously monitors critical system files, registry keys, and other configurations for unauthorized changes, alerting security personnel when modifications occur. This directly addresses the requirement to detect persistence and privilege escalation attempts.
Why the other options are wrong
- A. Network anomaly detection focuses on unusual network traffic patterns, not host-based file or registry changes.
- B. Behavioral analysis engines detect unusual process behavior but might not specifically flag a change to a registry key as a primary alert without other contextual factors.
- D. Signature-based malware detection identifies known malicious files but doesn't monitor for changes to legitimate system files or registry keys by unknown means.
File Integrity Monitoring (FIM)
A security control that monitors and alerts on unauthorized changes to critical system files, directories, and registry keys.
- Detects tampering, malware, and configuration drift.
- Often a core component of HIDS/SIEM solutions.
- Compares current state to a baseline.
Memory trick: A good HIDS watches your 'files' and 'behaviors', not just 'network' or 'signatures'.