EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesEasy
A security analyst is investigating a suspected intrusion on a Linux server. They need to determine if any unauthorized modifications have been made to critical system files. Which of the following tools is BEST suited for this purpose by comparing current file states against a known good baseline?
- AMetasploit
- BTripwire
- CNmap
- DWireshark
Show answer & explanationAnswer & explanation
Correct answer: B. Tripwire
Tripwire is a host-based intrusion detection system (HIDS) specifically designed for file integrity monitoring. It creates a baseline of critical system files and then periodically checks for any unauthorized changes by comparing current file hashes with the baseline.
Why the other options are wrong
- A. Metasploit is an exploitation framework, not a file integrity monitoring tool.
- C. Nmap is a network scanner, not used for file integrity monitoring.
- D. Wireshark is a packet analyzer, used for network traffic inspection.
File Integrity Monitoring
The process of validating the integrity of operating system and application software files by comparing their current state to a known, trusted baseline.
- Detects unauthorized changes, deletions, or additions to files.
- Often uses cryptographic hashes (e.g., MD5, SHA256) for comparison.
- Crucial for detecting rootkits and other persistent malware.
Memory trick: To 'analyze' system files for 'integrity', use a 'tripwire' to catch changes.