Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium
A security analyst is performing host-based intrusion detection on a critical Linux web server. They want to monitor for unauthorized modifications to core system binaries (e.g., /bin/ls, /usr/bin/sudo) in real-time. Which host-based security technology would be most effective for detecting such changes immediately?
- AImplementing a web application firewall (WAF) on the server.
- BRegularly scheduled 'find' commands to check modification times.
- CFile Integrity Monitoring (FIM) using a tool like AIDE or Tripwire.
- DReviewing '/var/log/auth.log' for root login attempts.
Show answer & explanationAnswer & explanation
Correct answer: C. File Integrity Monitoring (FIM) using a tool like AIDE or Tripwire.
File Integrity Monitoring (FIM) solutions (like AIDE or Tripwire) are specifically designed to detect unauthorized changes to critical system files. They work by creating a database of cryptographic hashes and other attributes of files and then regularly comparing the current state of files against this baseline, alerting on any discrepancies.
Why the other options are wrong
- A. A WAF protects web applications from attacks and would not monitor the integrity of underlying operating system binaries.
- B. Regular 'find' commands are a manual and less efficient way to check for changes, and they might miss subtle modifications or changes to attributes other than modification time.
- D. Auth.log monitors authentication events and would not directly detect modifications to system binaries.
File Integrity Monitoring (FIM)
A security control that monitors critical system and application files for unauthorized changes by comparing their current state (e.g., hashes) to a known good baseline.
- Detects tampering with executables, configurations.
- Uses cryptographic hashes for integrity checks.
- Alerts on deviations from a baseline.
Memory trick: Integrity monitoring keeps files as they should be.