When File Integrity Monitoring is activated, which two items are specifically monitored?

Prepare effectively for the Sophos Endpoint and Server Engineer Test. Utilize flashcards and multiple-choice questions with detailed hints and explanations. Ace your exam with confidence!

File Integrity Monitoring (FIM) is a security control that helps track changes to files and directories to detect unauthorized modifications. When activated, it specifically monitors files and registry entries. This function is critical for maintaining the integrity of system configurations and sensitive files, as changes to these elements can indicate potential security breaches or unauthorized access.

Monitoring files ensures that any alterations, whether accidental or malicious, are recorded. Similarly, tracking changes to registry entries helps in identifying unauthorized changes to system settings, which could compromise the security posture of the system. Thus, FIM serves as an essential tool in safeguarding the system by providing alerts on changes that could signal security threats.

The other options relate to various aspects of system operation or resource management, but they do not pertain to the core function of FIM, which focuses solely on monitoring the integrity of files and registry entries.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy