Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A security administrator has been asked to establish baseline monitoring for a set of Linux web servers so that unexpected changes to critical system files are detected quickly. The administrator wants the tool to compute cryptographic hashes of files, store them, and alert when they change. Which of the following should the administrator deploy to meet this requirement?

⚠ Common exam trap

Many exam-takers confuse general monitoring platforms with file integrity monitoring, when only a hashing-based agent detects changes to local files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A host-based intrusion detection system performing file integrity monitoring

Detecting unexpected modification of critical system files requires periodic or real-time hashing of those files against a stored known-good baseline. File integrity monitoring, delivered by a host-based intrusion detection agent, performs exactly this function and generates alerts when hashes diverge, which no network sensor, log aggregator, or periodic vulnerability scan accomplishes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A vulnerability scanner scheduled to run weekly against the server group

    Why it's wrong here

    A vulnerability scanner identifies known weaknesses such as missing patches and misconfigurations at the time of the scan; it does not continuously monitor file hashes or alert on change. A file altered between weekly scans would be invisible, and the scanner's findings describe exposure rather than detecting unauthorized modification of critical system files.

  • ✗

    A network-based intrusion detection system watching the web server subnet

    Why it's wrong here

    A network-based intrusion detection system inspects packet traffic for malicious patterns; it does not hash files or maintain a known-good baseline of local system files. File modifications made through legitimate channels, such as a compromised administrative session, can occur without generating distinctive network signatures, so this tool cannot satisfy the stated file change detection requirement.

  • ✗

    A security information and event management platform with syslog collection only

    Why it's wrong here

    A SIEM aggregates and correlates logs but does not itself hash files or compare them against stored baselines unless a separate agent supplies that data. With syslog collection alone the platform only receives what hosts choose to emit, and ordinary file modification on Linux generates no syslog entry, so unexpected changes would go undetected under this design.

  • ✓

    A host-based intrusion detection system performing file integrity monitoring

    Why this is correct

    File integrity monitoring computes cryptographic hashes of critical files, stores the known-good values, and alerts when a hash changes, which is exactly the requirement. A host-based intrusion detection system running file integrity monitoring on each server provides this baseline change detection, making it the appropriate control for detecting unexpected modification of system files.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.