SY0-701 exam dumps

SY0-701 practice question 332 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 332

Single answerFile integrity monitoring

A security administrator enables file integrity monitoring (FIM) on a Linux-based public web server after a recent incident involving unauthorized changes to website content. The administrator wants to detect if critical web application files are modified, while minimizing false positives from normal system activity such as log rotation and temporary file updates. Which action would BEST meet this requirement?

  1. A

    Configure FIM to baseline the web root and application configuration files, alert on hash changes to those files, and exclude log and temporary directories from monitoring

  2. B

    Configure FIM to monitor all files on the server equally and generate alerts only when file permissions change

  3. C

    Use full-disk encryption on the server so unauthorized file modifications cannot occur without the encryption key

  4. D

    Schedule weekly vulnerability scans of the server and treat any scan result changes as evidence of file tampering

Show answer and explanation

Correct answer: A

Explanation

File integrity monitoring is intended to detect unauthorized or unexpected changes to important files by comparing their current state to a known-good baseline. In this scenario, the best practice is to scope monitoring to high-value targets such as web content, scripts, binaries, and configuration files, then tune exclusions for frequently changing files like logs, cache, and temp locations. This improves signal-to-noise ratio and supports actionable alerting. Industry guidance commonly aligns with this approach, including the concept of monitoring critical system and application files while reducing unnecessary alerts from expected operational changes. For example, NIST guidance on integrity controls and CIS best practices emphasize establishing baselines for important files and monitoring for unauthorized modification. Security professionals should recognize that FIM is an integrity control, whereas options like encryption and vulnerability scanning serve different security purposes.

  • A. Correct.

    Correct. This is the most effective and practical FIM implementation for the scenario. FIM works by creating a trusted baseline of important files and then detecting changes such as modified hashes, permissions, ownership, or timestamps. Monitoring the web root and application configuration files focuses on the assets most likely to be targeted in website defacements or malicious code insertion. Excluding log and temporary directories reduces noise from expected changes like log rotation, session files, caches, and temp file creation, which helps minimize false positives.

  • B. Incorrect.

    Incorrect. Monitoring all files equally is inefficient and usually creates excessive noise, especially on active systems where many files change routinely. In addition, limiting alerts only to permission changes misses one of the primary uses of FIM: detecting content changes through cryptographic hashes or similar methods. An attacker can alter a file's contents without changing permissions, so this approach would leave a major gap.

  • C. Incorrect.

    Incorrect. Full-disk encryption protects data at rest, such as when a system is powered off or a drive is stolen, but it does not provide ongoing detection of file modifications on a running system. Once the server is booted and the disk is unlocked, processes with sufficient access can still modify files. This option confuses confidentiality protection with integrity monitoring.

  • D. Incorrect.

    Incorrect. Vulnerability scans are useful for finding missing patches, insecure configurations, and exposed services, but they are not a substitute for FIM. A vulnerability scanner does not continuously track whether specific protected files were altered. Changes in scan results might indicate configuration drift or new vulnerabilities, but they do not directly provide file-level integrity assurance.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam