From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Host sensors

Host sensors

- [Instructor] In addition to all the network-based tools and sensors, there's also a few host-based sensors that we need to discuss that we use inside of our security assessments. Things like file integrity monitoring, antivirus or anti-malware solutions, and data loss prevention sensors. Now, file Integrity monitoring, or FIM, is a host-based intrusion detection system that creates a hash digest for every file that's being monitored. If the file is changed or altered, that hash of that file is also going to be altered, and this will create an alert in the system. We usually conduct this technique on operating system and application files. File integrity monitoring is also a requirement for PCI-DSS, Sarbanes-Oxley, Federal Information Security Management Act, Health Insurance Portability and Accountability Act, and Critical Security Functions. As you already know, it's also imperative that we have antivirus or anti-malware protection installed on our host as a protection mechanism…

Contents