SSCP Security Operations and Administration Practice Question
A security administrator is implementing a new file integrity monitoring (FIM) solution on critical servers. The administrator needs to ensure that the solution can detect unauthorized changes to system binaries and configuration files. Which of the following should the administrator configure to establish a trusted baseline for the FIM solution?
⚠ Common exam trap
A common mix-up: candidates confuse file access auditing or backups with file integrity baseline creation, when the key is to capture and protect a cryptographic hash of file contents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Generate cryptographic hashes of the files and store them in a secure, offline location.
To establish a trusted baseline for FIM, the administrator must capture the current state of critical files, typically by generating cryptographic hashes. Storing these hashes securely offline prevents tampering. File access auditing, backups, and registry monitoring do not provide a file content baseline. Therefore, the correct action is to generate and securely store file hashes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Generate cryptographic hashes of the files and store them in a secure, offline location.
Why this is correct
FIM works by comparing current file hashes against a known good baseline. Storing the baseline hashes offline prevents an attacker who compromises the server from altering the baseline to hide their changes. This ensures the integrity of the comparison and allows detection of unauthorized modifications. Cryptographic hashes provide a unique fingerprint for each file, so any change will be detected.
- ✗
Schedule a daily full backup of the critical servers and store the backups on a separate network share.
Why it's wrong here
Backups are essential for recovery, but they do not provide a real-time integrity baseline for FIM. FIM needs a snapshot of file hashes to compare against on a frequent basis. Backups may be taken less frequently and are not designed to detect changes between backup intervals. Moreover, restoring from backup does not help detect unauthorized changes; it only helps recover from them.
- ✗
Configure the FIM solution to monitor the Windows Registry for changes to critical keys.
Why it's wrong here
Monitoring the registry is a specific FIM capability, but it does not establish a baseline for file integrity. The question asks for establishing a trusted baseline for system binaries and configuration files. Registry monitoring is useful for detecting configuration changes in Windows, but it is not the method to baseline files. The baseline must be created from the files themselves, typically via hashing.
- ✗
Enable auditing of file access events in the operating system's security log.
Why it's wrong here
Auditing file access events records who accessed files and when, but it does not provide a baseline of file contents to detect changes. FIM requires a known good state to compare against. While auditing is valuable for monitoring access, it does not satisfy the requirement to detect unauthorized modifications to file contents. It is a complementary control, not a baseline.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.