SY0-701 exam dumps

SY0-701 practice question 333 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 333

Single answerFile integrity monitoring

A security administrator is deploying file integrity monitoring (FIM) on a public-facing Linux web server after a recent incident in which attackers modified application files without immediately triggering antivirus alerts. The administrator wants the solution to quickly detect unauthorized changes to critical system and web application files while minimizing false positives from normal patching and log activity. Which action would BEST meet this requirement?

  1. A

    Create a cryptographic hash baseline for approved system and application files, exclude frequently changing files such as logs, and schedule comparisons with alerting for unexpected changes

  2. B

    Enable full packet capture on the server's network interface so modified files can be reconstructed from network traffic if an incident occurs

  3. C

    Increase antivirus scan frequency to every 15 minutes and quarantine any file that differs from the previous scan

  4. D

    Configure the SIEM to retain web server logs for one year and generate alerts when disk utilization changes significantly

Show answer and explanation

Correct answer: A

Explanation

The best answer is to deploy FIM using a known-good baseline of critical files and compare current file states to that baseline using cryptographic hashes or similar integrity checks. This aligns with common security best practices for detecting unauthorized changes to operating system files, application binaries, configuration files, and web content. To reduce noise, organizations typically tune FIM by excluding highly volatile files such as logs and by updating the baseline through approved change-management processes after authorized patches or application updates. This approach is consistent with guidance in NIST SP 800-53, which includes file integrity monitoring under SI-7 (Software, Firmware, and Information Integrity), and with CIS Controls guidance on monitoring and maintaining asset integrity. In contrast, packet capture, antivirus frequency changes, and generic SIEM storage settings may support broader detection or response efforts but do not replace the core purpose of FIM.

  • A. Correct.

    Correct. File integrity monitoring works by establishing a known-good baseline, commonly using cryptographic hashes, and then comparing monitored files against that baseline to detect unauthorized changes. Excluding files that change routinely, such as logs, temporary files, or patch-managed directories where appropriate, helps reduce false positives. This is the most direct and practical way to detect tampering with critical binaries, configuration files, and web content.

  • B. Incorrect.

    Incorrect. Full packet capture can support forensic investigations, but it is not a file integrity monitoring control. It does not directly baseline files on disk or reliably detect local file modifications, especially if the change did not traverse the network in a reconstructable way.

  • C. Incorrect.

    Incorrect. Antivirus is designed primarily to detect known malicious content or suspicious behavior, not to serve as a full file integrity monitoring solution. A file changing between scans does not automatically indicate malicious activity, and quarantining any changed file would create major operational issues and many false positives during legitimate updates.

  • D. Incorrect.

    Incorrect. Long-term log retention and SIEM alerting are useful for monitoring and investigations, but they do not provide direct file integrity validation. Disk utilization changes are also too indirect to identify unauthorized modification of specific files and would likely miss targeted tampering.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam