FIM is a security measure that detects unauthorized changes to files, configurations, or system settings. It logs and alerts administrators of anomalies, making it a key detective control.
Why FIM is a Detective Control
It does not prevent changes but monitors and reports them for further investigation.
Enhances visibility and auditability of system changes.
Comparison of Options
A. Network-based security preventative control: Preventative controls aim to block issues before they occur.
B. Software segmentation control: Refers to dividing software components, not monitoring.
D. User segmentation control: Focuses on access control policies for users, unrelated to file integrity.
EC-Council References
FIM is emphasized as a critical part of continuous monitoring and detection mechanisms in security frameworks taught by EC-Council.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit