An organization wants to immediately detect unauthorized modifications made to critical system configuration files on a server. Which of the following technical controls is MOST effective for this purpose?
- Deploying File Integrity Monitoring (FIM) software to inspect baseline file hashes.Cevap
- BConfiguring network perimeter firewalls to block incoming unauthorized file transfer ports.
- CSetting up a network honeypot to trap unauthorized users attempting system changes.
- DApplying network layer encryption across all server management VLANs.
Cevap
Deploying File Integrity Monitoring (FIM) software to inspect baseline file hashes.
File Integrity Monitoring (FIM) is specifically designed to monitor system and application files by comparing their current cryptographic hashes against established baseline hashes. If an unauthorized user or process modifies a protected file, FIM detects the hash mismatch and alerts security administrators immediately.
Adım Adım Çözüm
Anahtar Kavram
File Integrity Monitoring (FIM) for Host Hardening
Tahmini Süre:45s