Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisEasy

A security analyst is reviewing a host-based intrusion detection system (HIDS) alert that indicates a critical system file (`C:\Windows\System32\ntoskrnl.exe`) has had its hash value changed. The HIDS uses a pre-established baseline for comparison. This type of alert most directly signifies a potential:

  1. AAttempted modification of a core operating system component.
  2. BBrute-force attack on a user account.
  3. CDenial-of-service (DoS) attack.
  4. DUnauthorized network port scan.
Show answer & explanation

Correct answer: A. Attempted modification of a core operating system component.

A change in the hash value of a critical system file like `ntoskrnl.exe` (the Windows kernel) strongly indicates an unauthorized modification. This is a common tactic for rootkits or other advanced malware to gain deep system control or evade detection, directly signaling an attempted compromise of a core OS component.

Why the other options are wrong

  • B. A brute-force attack would be indicated by multiple failed login attempts, not a file hash change.
  • C. A DoS attack typically involves overwhelming system resources or network bandwidth, not modifying specific system files.
  • D. An unauthorized network port scan would be detected by network logs or a network intrusion detection system (NIDS), not by a HIDS monitoring file integrity.

File Hash Integrity Check

The process of comparing the cryptographic hash of a file to a known good hash value to detect unauthorized modifications or corruption.

  • Essential for detecting tampering and malware.
  • Often performed by File Integrity Monitoring (FIM) systems.
  • Any mismatch indicates a change to the file.

Memory trick: A HIDS screams if a 'file' changes, a 'process' acts weird, or a 'log' looks fishy.

More Host-Based Analysis questions