Courseiva
hardMultiple Choice

XK0-006 Practice Question: An administrator is investigating a system that…

An administrator is investigating a system that may have been compromised. The 'aide' database was created six months ago. After running 'aide --check', many files in /usr/bin are reported as changed. Which action should the administrator take first to identify the cause?

⚠ Common exam trap

A common mix-up: candidates think updating the AIDE database (Option B) is the logical next step to stop false alerts, but this would overwrite the baseline and eliminate the ability to detect the compromise, whereas the correct first action is to cross-verify with the package manager's own integrity database.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Compare the checksums with the original package manager database (rpm -V).

The AIDE database is six months old, so any changes to system binaries in /usr/bin since then would be flagged. The first step should be to verify whether these changes are legitimate (e.g., from package updates) or malicious by comparing the current file checksums against the RPM package manager's database using 'rpm -V'. This distinguishes expected updates from unauthorized modifications without relying on the outdated AIDE baseline.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the verbosity of AIDE to see which attributes changed.

    Why it's wrong here

    Verbosity only expands the report of which attributes differ; it cannot reveal why /usr/bin files changed, so it does not identify a cause. It is tempting because verbose output is genuinely useful when a single file's metadata change needs detailed inspection, not a mass change across a directory.

  • ✗

    Update the AIDE database with 'aide --update'.

    Why it's wrong here

    Updating the database overwrites the baseline with the current, possibly compromised, file hashes, destroying the evidence needed to identify what changed. It is tempting because --update is the normal way to accept legitimate changes after patching, but that applies only once changes are verified as benign.

  • ✓

    Compare the checksums with the original package manager database (rpm -V).

    Why this is correct

    Comparing against the RPM database verifies whether the changed binaries match their vendor-shipped checksums, distinguishing genuine tampering from legitimate package updates applied since the AIDE database was built six months ago. This directly addresses the stem's need to identify the cause of the /usr/bin discrepancies before assuming compromise.

  • ✗

    Restore the original files from backup.

    Why it's wrong here

    Restoring from backup overwrites the altered binaries before any forensic analysis, destroying the evidence that would identify the cause. It is tempting because restoration is the correct remediation step once a compromise is confirmed and the entry vector is understood, but it must follow, not precede, investigation.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.