SSCP Risk Identification, Monitoring, and Analysis Practice Question
A security administrator has been asked to establish baseline monitoring for a set of Linux web servers so that unexpected changes to critical system files are detected quickly. The administrator wants the tool to compute cryptographic hashes of files, store them, and alert when they change. Which of the following should the administrator deploy to meet this requirement?
⚠ Common exam trap
Many exam-takers confuse general monitoring platforms with file integrity monitoring, when only a hashing-based agent detects changes to local files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A host-based intrusion detection system performing file integrity monitoring
Detecting unexpected modification of critical system files requires periodic or real-time hashing of those files against a stored known-good baseline. File integrity monitoring, delivered by a host-based intrusion detection agent, performs exactly this function and generates alerts when hashes diverge, which no network sensor, log aggregator, or periodic vulnerability scan accomplishes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A vulnerability scanner scheduled to run weekly against the server group
Why it's wrong here
A vulnerability scanner identifies known weaknesses such as missing patches and misconfigurations at the time of the scan; it does not continuously monitor file hashes or alert on change. A file altered between weekly scans would be invisible, and the scanner's findings describe exposure rather than detecting unauthorized modification of critical system files.
- ✗
A network-based intrusion detection system watching the web server subnet
Why it's wrong here
A network-based intrusion detection system inspects packet traffic for malicious patterns; it does not hash files or maintain a known-good baseline of local system files. File modifications made through legitimate channels, such as a compromised administrative session, can occur without generating distinctive network signatures, so this tool cannot satisfy the stated file change detection requirement.
- ✗
A security information and event management platform with syslog collection only
Why it's wrong here
A SIEM aggregates and correlates logs but does not itself hash files or compare them against stored baselines unless a separate agent supplies that data. With syslog collection alone the platform only receives what hosts choose to emit, and ordinary file modification on Linux generates no syslog entry, so unexpected changes would go undetected under this design.
- ✓
A host-based intrusion detection system performing file integrity monitoring
Why this is correct
File integrity monitoring computes cryptographic hashes of critical files, stores the known-good values, and alerts when a hash changes, which is exactly the requirement. A host-based intrusion detection system running file integrity monitoring on each server provides this baseline change detection, making it the appropriate control for detecting unexpected modification of system files.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.