EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium

A system administrator is hardening a critical Linux server. They want to implement a mechanism to quickly detect unauthorized modifications to important system files and binaries, such as '/bin/ls', '/bin/su', or '/etc/passwd'. Which type of security control is best suited for this purpose?

  1. ASecurity Information and Event Management (SIEM)
  2. BData Loss Prevention (DLP)
  3. CHost-based Intrusion Detection System (HIDS) with File Integrity Monitoring (FIM)
  4. DNetwork Intrusion Detection System (NIDS)
Show answer & explanation

Correct answer: C. Host-based Intrusion Detection System (HIDS) with File Integrity Monitoring (FIM)

File Integrity Monitoring (FIM) is a core component of a Host-based Intrusion Detection System (HIDS) specifically designed to detect changes to critical system files by comparing their current state (e.g., hashes, permissions, timestamps) against a known baseline. This directly addresses the need to detect unauthorized modifications to '/bin/ls', '/bin/su', or '/etc/passwd'.

Why the other options are wrong

  • A. SIEM aggregates and analyzes logs from various sources, but relies on other systems (like FIM) to generate the alerts about file changes.
  • B. DLP focuses on preventing sensitive data from leaving the organization, not detecting unauthorized file modifications.
  • D. NIDS monitors network traffic for suspicious activity, not changes to local files.

File Integrity Monitoring (FIM)

A security control that monitors and detects unauthorized or suspicious changes to critical system files, configuration files, and content files by comparing their current state against a known, trusted baseline.

  • Uses hashing algorithms to create file baselines.
  • Alerts administrators to any deviations from the baseline.
  • Essential for detecting rootkits, malware, and unauthorized system modifications.

Memory trick: Host security: FIM for files, HIDS for events, Antivirus for malware, Firewall for access.

More System Hacking Phases and Attack Techniques questions