Skip to main content
Offline·Progress is saved on this device and syncs the next time you open the app online.
Security Operations & Monitoring

FIM

File Integrity Monitoring

Detects unauthorized changes to critical files by comparing against a baseline.

FIM establishes a trusted baseline, often using cryptographic hashes, and alerts when monitored files, directories, or configurations change unexpectedly. This helps detect malware persistence, unauthorized tampering, and insider modification, and it supports compliance regimes that require change detection on critical systems. Because legitimate updates also trigger alerts, effective deployments whitelist expected activity such as patch cycles to control noise. The exam value is recognizing FIM as a detective control that surfaces integrity violations rather than preventing them, frequently feeding alerts into a SIEM.

Related terms

Looking FIM up is step one. Getting tested on it is step two.

A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.

Not affiliated with or endorsed by CompTIA.