mediumMultiple Choice
CAS-004 Practice Question: Is the MOST effective way to detect unauthorized…
Which of the following is the MOST effective way to detect unauthorized changes to critical files?
⚠ Common exam trap
Watch out — candidates often confuse detection (FIM) with prevention (antivirus) or recovery (backups), or mistakenly think an IDS can monitor file integrity when it is designed for network-level anomaly detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
File integrity monitoring
File integrity monitoring (FIM) is the most effective method for detecting unauthorized changes to critical files because it uses cryptographic hashing (e.g., SHA-256) to create a baseline of file states and then periodically re-computes hashes to identify any alterations. Unlike other security controls, FIM specifically focuses on the integrity of file content, metadata, and permissions, providing immediate alerts when a deviation from the baseline occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Antivirus software
Why it's wrong here
Antivirus matches known malware signatures and heuristics; an attacker editing a configuration or script with legitimate tools triggers no signature, so the change goes unseen. Antivirus suits endpoint malware prevention, whereas detecting file tampering requires cryptographic hashing against a stored baseline.
- ✗
Intrusion detection system
Why it's wrong here
An IDS inspects network traffic and host activity for attack signatures, not file content integrity, so a modified critical file altered through a legitimate channel passes unnoticed. It is tempting because IDS genuinely detects intrusions and policy violations across a network, which suits perimeter and host monitoring rather than file-change verification.
- ✗
Regular backups
Why it's wrong here
Backups restore data after loss; they do not compare current file state against a known-good baseline, so an unauthorised edit stays undetected until restore. Backups are the right control for recovery and ransomware resilience, where the goal is regaining data rather than identifying that a change occurred.
- ✓
File integrity monitoring
Why this is correct
File integrity monitoring continuously hashes critical files and compares results against a known-good baseline, generating alerts the moment content changes. This directly satisfies the stem's requirement to detect unauthorised modification, unlike access logging, which records who touched a file but not whether its contents were altered.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.