GSEC Defense in Depth Practice Question
A hospital's billing server runs Windows Server 2019 and stores insurance claim data. The security team wants to add a control that will detect unauthorized modification of the claim files even if an attacker gains administrative access to the operating system. Which control best meets this requirement?
⚠ Common exam trap
The trap here is assuming that administrative access logging or disk encryption will reveal file tampering, when only a hash-based baseline comparison can prove content changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement file integrity monitoring (FIM) using SHA-256 hashes of the claim files and schedule regular baseline comparisons.
Detecting unauthorized modification of stored data requires a mechanism that can prove whether contents changed, regardless of the attacker's privilege level. Hash-based file integrity monitoring establishes a trusted baseline and alerts on any deviation, which is exactly what the hospital needs. Encryption and auditing address confidentiality and visibility respectively, and neither produces cryptographic evidence of tampering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Windows Audit Policy to log all file access events to the Security event log.
Why it's wrong here
Windows auditing can record access attempts, but an attacker with administrative rights can clear or tamper with the event log. Auditing also generates enormous volume on a busy billing server, and it does not provide a cryptographic baseline to prove whether file contents changed. It is weaker than hash-based integrity monitoring for this purpose.
- ✗
Enable Windows BitLocker full-disk encryption on the billing server's data volume.
Why it's wrong here
BitLocker protects data confidentiality when the disk is offline or the host is powered down, but once the operating system is running and unlocked, files are transparently decrypted. An attacker with administrative access can modify claim files freely, and BitLocker provides no mechanism to detect those changes. It is a confidentiality control, not an integrity-detection control.
- ✗
Deploy a host-based intrusion prevention system (HIPS) that blocks suspicious process execution on the billing server.
Why it's wrong here
A HIPS monitors and blocks suspicious process behavior on the host, but it does not create a verifiable record of file contents. An attacker with administrative access could disable the agent or alter files without the HIPS producing cryptographic evidence of tampering. It addresses prevention and some detection, not integrity verification of stored claim data.
- ✓
Implement file integrity monitoring (FIM) using SHA-256 hashes of the claim files and schedule regular baseline comparisons.
Why this is correct
File integrity monitoring computes cryptographic hashes of the claim files and stores a known-good baseline. On subsequent scans, any modification produces a hash mismatch, alerting the team even if the attacker used legitimate administrative privileges. This directly satisfies the requirement to detect unauthorized modification independently of access controls.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.