CAS-003 · Question #947
An analyst discovers the following while reviewing some recent activity logs: Which of the following tools would MOST likely identify a future incident in a timely manner?
The correct answer is B. File integrity monitoring. File Integrity Monitoring (FIM) continuously watches for unauthorized or unexpected changes to files, configurations, and system binaries. When activity logs show suspicious modifications (e.g., altered system files, changed configurations, or tampered logs), FIM is…
Question
An analyst discovers the following while reviewing some recent activity logs:
Which of the following tools would MOST likely identify a future incident in a timely manner?
Exhibit
Options
- ADDoS protection
- BFile integrity monitoring
- CSCAP scanner
- DProtocol analyzer
How the community answered
(43 responses)- A2% (1)
- B79% (34)
- C7% (3)
- D12% (5)
Explanation
File Integrity Monitoring (FIM) continuously watches for unauthorized or unexpected changes to files, configurations, and system binaries. When activity logs show suspicious modifications (e.g., altered system files, changed configurations, or tampered logs), FIM is purpose-built to detect exactly those changes in near real-time and generate alerts. DDoS protection (A) addresses availability attacks, not file-level tampering. A SCAP scanner (C) performs periodic compliance checks, not real-time detection. A protocol analyzer (D) captures network traffic but would not efficiently detect file-level changes indicated in the logs.
Topics
Community Discussion
No community discussion yet for this question.
