Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisMedium

A forensic investigator is analyzing a Linux server after a suspected compromise. The attacker is believed to have modified system binaries to maintain persistence and evade detection. Which of the following commands would be most effective for verifying the integrity of installed packages against their original state on a Debian-based system?

  1. Aapt-get check
  2. Brpm -Va
  3. Cyum check-update
  4. Ddpkg --verify
Show answer & explanation

Correct answer: D. dpkg --verify

On Debian-based systems, `dpkg --verify` (or `debsums`) is used to check the integrity of installed packages by comparing file checksums and other metadata against the package's original manifest. This helps identify unauthorized modifications to system binaries.

Why the other options are wrong

  • A. apt-get check is used to check for broken dependencies in the APT package cache, not file integrity of installed packages.
  • B. rpm -Va is used for verifying package integrity on Red Hat-based systems (RPM Package Manager), not Debian.
  • C. yum check-update is used on Red Hat-based systems to check for available package updates, not integrity.

dpkg --verify

A command on Debian-based Linux systems used to check the integrity of installed packages by comparing files against their known good state.

  • Compares file checksums
  • Identifies unauthorized modifications
  • Specific to Debian/Ubuntu systems

Memory trick: Debian's dpkg verifies package purity.

More Host-Based Analysis questions