Courseiva
Defense in Depth →mediumMultiple Choice

GSEC Defense in Depth Practice Question

A hospital's IT team is designing layered defenses for its electronic health record (EHR) system. They already have perimeter firewalls, network intrusion prevention, and endpoint antivirus. The CISO wants to add a control that detects unauthorized modification of EHR database records and alerts the security team in near real time. Which control best fills this gap while preserving defense in depth?

⚠ Common exam trap

The trap here is assuming that any logging or encryption control will detect data tampering, when only integrity-focused monitoring actually compares content against a known-good state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

File integrity monitoring (FIM) with cryptographic hashing on the EHR database files

The scenario requires a detective control that specifically identifies unauthorized changes to EHR database records. File integrity monitoring with cryptographic hashing provides exactly that by comparing current file hashes to a trusted baseline and alerting on mismatch. The other options either duplicate existing preventive controls or provide logging without integrity detection, leaving the data-layer gap unaddressed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implementing full-disk encryption on the EHR database servers

    Why it's wrong here

    Full-disk encryption protects data at rest if the physical disk is stolen, but it does not detect unauthorized modification of records while the system is running and unlocked. It is a preventive confidentiality control, not a detective integrity control. It would not alert the security team to tampering with EHR records.

  • ✓

    File integrity monitoring (FIM) with cryptographic hashing on the EHR database files

    Why this is correct

    FIM computes cryptographic hashes of critical files and compares them against a known-good baseline, so any unauthorized modification of EHR database records triggers an alert. This adds a detective control at the data layer, complementing existing preventive network and host controls. It directly addresses the need for near-real-time detection of record tampering without disrupting clinical workflows.

  • ✗

    Configuring syslog forwarding from the EHR servers to a central SIEM

    Why it's wrong here

    Syslog forwarding collects and centralizes log events, which is useful, but it does not by itself detect unauthorized modification of database records unless the application generates specific integrity events. It is a transport mechanism, not a data-integrity detective control. The scenario calls for detection of record tampering, which syslog alone does not provide.

  • ✗

    Deploying an additional host-based firewall on the EHR application servers

    Why it's wrong here

    A host-based firewall controls network traffic to and from the server but does not inspect or detect changes to database records. It would duplicate the existing preventive network controls rather than add a detective capability at the data layer. The scenario already has network and endpoint controls, so this does not fill the stated gap.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.