Cisco CyberOps Associate (CBROPS) 200-201Host-Based AnalysisHard
A security analyst is performing host-based forensics on a Linux server following a suspected compromise. The attacker is believed to have tampered with system binaries to maintain backdoor access and evade detection. Which command-line utility is most effective for verifying the integrity of installed packages and system binaries against known good checksums or cryptographic hashes?
- Arpm -Va or dpkg --verify
- Bnetstat -tulnp
- Cls -laR /
- Dfind / -perm /6000
Show answer & explanationAnswer & explanation
Correct answer: A. rpm -Va or dpkg --verify
`rpm -Va` (for RPM-based systems like Red Hat/CentOS) and `dpkg --verify` (for Debian-based systems like Ubuntu) are utilities specifically designed to verify the integrity of installed packages, comparing current file attributes and checksums against the package's original manifest, which is crucial for detecting tampered binaries.
Why the other options are wrong
- B. `netstat -tulnp` displays active network connections and listening ports, useful for network forensics but not for file integrity.
- C. `ls -laR /` lists all files and directories recursively but does not perform integrity checks.
- D. `find / -perm /6000` searches for files with SUID/SGID permissions, which is useful for privilege escalation but not for verifying file integrity against a baseline.
Linux Package Integrity Check
Utilities (`rpm -Va`, `dpkg --verify`) used on Linux systems to verify the integrity of installed packages and their constituent files against official package manifests.
- Detects unauthorized modifications to system binaries.
- Compares file attributes, checksums, and permissions.
- Crucial for detecting rootkits and backdoors.
Memory trick: When a Linux system feels 'off', check 'packages', 'connections', or 'permissions', not just a file 'list'.