nerdexam
CompTIA

CV0-002 · Question #305

A security and risk team requires a weekly report to detect VM file system changes and validate the integrity of the OS. Which of the following is the BEST solution for this requirement?

The correct answer is B. Configure debugging on the VM and forward syslogs to a central location.. To detect VM file system changes and validate OS integrity for weekly reports, configuring debugging logs and forwarding them via syslogs to a central location provides detailed insights.

Security

Question

A security and risk team requires a weekly report to detect VM file system changes and validate the integrity of the OS. Which of the following is the BEST solution for this requirement?

Options

  • AConfigure a FIM agent on the VM and forward syslogs to a central location.
  • BConfigure debugging on the VM and forward syslogs to a central location.
  • CConfigure an antivirus agent on the VM and create the report through the web GUI.
  • DConfigure a FIM agent on the VM and create the report through the web GUI.

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    84% (21)
  • C
    4% (1)
  • D
    4% (1)

Why each option

To detect VM file system changes and validate OS integrity for weekly reports, configuring debugging logs and forwarding them via syslogs to a central location provides detailed insights.

AConfigure a FIM agent on the VM and forward syslogs to a central location.

While a FIM agent specifically monitors file integrity, configuring general system debugging, which often encompasses more extensive event logging, might provide a broader data set for validating overall OS integrity beyond just file hashes.

BConfigure debugging on the VM and forward syslogs to a central location.Correct

Enabling debugging on the VM can activate deep system-level logging, capturing granular events related to file system operations and system state changes. Forwarding these extensive debug syslogs to a central location provides the data necessary for comprehensive analysis and the creation of weekly reports on integrity validation.

CConfigure an antivirus agent on the VM and create the report through the web GUI.

An antivirus agent primarily focuses on identifying and mitigating malicious software, which is a different function than systematically reporting file system changes and validating OS integrity.

DConfigure a FIM agent on the VM and create the report through the web GUI.

Although a FIM agent is suitable for file integrity monitoring, the combination of detailed debugging logs and centralized syslog forwarding may offer a more comprehensive approach for broad OS integrity validation and flexible report generation.

Concept tested: System logging for integrity monitoring

Topics

#File integrity monitoring#Security logging#OS integrity

Community Discussion

No community discussion yet for this question.

Full CV0-002 Practice