A system administrator is hardening a critical Linux server. They want to implement a mechanism to quickly detect unauthorized modifications to important system files and binaries, such as '/bin/ls', '/bin/su', or '/etc/passwd'. Which type of security control is best suited for this purpose?
- ASecurity Information and Event Management (SIEM)
- BData Loss Prevention (DLP)
- CHost-based Intrusion Detection System (HIDS) with File Integrity Monitoring (FIM)
- DNetwork Intrusion Detection System (NIDS)
Show answer & explanationAnswer & explanation
Correct answer: C. Host-based Intrusion Detection System (HIDS) with File Integrity Monitoring (FIM)
File Integrity Monitoring (FIM) is a core component of a Host-based Intrusion Detection System (HIDS) specifically designed to detect changes to critical system files by comparing their current state (e.g., hashes, permissions, timestamps) against a known baseline. This directly addresses the need to detect unauthorized modifications to '/bin/ls', '/bin/su', or '/etc/passwd'.
Why the other options are wrong
- A. SIEM aggregates and analyzes logs from various sources, but relies on other systems (like FIM) to generate the alerts about file changes.
- B. DLP focuses on preventing sensitive data from leaving the organization, not detecting unauthorized file modifications.
- D. NIDS monitors network traffic for suspicious activity, not changes to local files.
File Integrity Monitoring (FIM)
A security control that monitors and detects unauthorized or suspicious changes to critical system files, configuration files, and content files by comparing their current state against a known, trusted baseline.
- Uses hashing algorithms to create file baselines.
- Alerts administrators to any deviations from the baseline.
- Essential for detecting rootkits, malware, and unauthorized system modifications.
Memory trick: Host security: FIM for files, HIDS for events, Antivirus for malware, Firewall for access.