Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisEasy
A security analyst is reviewing a host-based intrusion detection system (HIDS) alert that indicates a critical system file (`C:\Windows\System32\ntoskrnl.exe`) has had its hash value changed. The HIDS uses a pre-established baseline for comparison. This type of alert most directly signifies a potential:
- AAttempted modification of a core operating system component.
- BBrute-force attack on a user account.
- CDenial-of-service (DoS) attack.
- DUnauthorized network port scan.
Show answer & explanationAnswer & explanation
Correct answer: A. Attempted modification of a core operating system component.
A change in the hash value of a critical system file like `ntoskrnl.exe` (the Windows kernel) strongly indicates an unauthorized modification. This is a common tactic for rootkits or other advanced malware to gain deep system control or evade detection, directly signaling an attempted compromise of a core OS component.
Why the other options are wrong
- B. A brute-force attack would be indicated by multiple failed login attempts, not a file hash change.
- C. A DoS attack typically involves overwhelming system resources or network bandwidth, not modifying specific system files.
- D. An unauthorized network port scan would be detected by network logs or a network intrusion detection system (NIDS), not by a HIDS monitoring file integrity.
File Hash Integrity Check
The process of comparing the cryptographic hash of a file to a known good hash value to detect unauthorized modifications or corruption.
- Essential for detecting tampering and malware.
- Often performed by File Integrity Monitoring (FIM) systems.
- Any mismatch indicates a change to the file.
Memory trick: A HIDS screams if a 'file' changes, a 'process' acts weird, or a 'log' looks fishy.