ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your team is deploying a microservice in a Kubernetes cluster that must alert security staff if any executable or configuration file inside the running container is altered by an attacker, while keeping runtime overhead low and maintaining an audit trail. Which runtime control best meets this requirement?
Configure a watchdog process that restarts the microservice if it stops responding to health checks.
Mount the container file system as read-only to prevent changes to binaries and configuration files.
Deploy a file integrity monitoring agent that continuously compares cryptographic hashes of critical files inside the container.
Rely on image vulnerability scanning during the CI/CD pipeline before the container is deployed.
File integrity monitoring (FIM) establishes a cryptographic baseline hash of specified files when the container starts and then re-calculates hashes or watches in-kernel events to detect modifications. When a mismatch or unauthorized write occurs, the FIM agent raises an alert and records the event, providing both real-time notification and an audit record. A watchdog only checks liveness or performance, not file tampering. Pre-deployment image scanning is a build-time control and offers no visibility once the container is running. Mounting the file system read-only can reduce the attack surface but does not generate alerts or audit trails if an attacker succeeds in remounting or otherwise modifying files. Therefore, FIM is the most appropriate runtime control for the stated need.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a File Integrity Monitoring (FIM) agent in Kubernetes?
Open an interactive chat with Bash
How does a cryptographic hash help in monitoring file integrity?
Open an interactive chat with Bash
Why is mounting a container file system as read-only not enough for runtime security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .