nerdexam
CompTIA

CAS-003 · Question #216

A security incident responder discovers an attacker has gained access to a network and has overwritten key system files with backdoor software. The server was reimaged and patched offline. Which of…

The correct answer is D. File integrity monitor. File integrity monitor will monitor and detect changes to system files.

Enterprise Security Operations

Question

A security incident responder discovers an attacker has gained access to a network and has overwritten key system files with backdoor software. The server was reimaged and patched offline. Which of the following tools should be implemented to detect similar attacks?

Options

  • AVulnerability scanner
  • BTPM
  • CHost-based firewall
  • DFile integrity monitor
  • ENIPS

How the community answered

(47 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    2% (1)
  • D
    91% (43)

Explanation

File integrity monitor will monitor and detect changes to system files.

Topics

#file integrity monitoring#backdoor detection#incident response#system recovery

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice