CompTIA A+ Core 2 (220-1202)SecurityHard

A technician is troubleshooting a Windows 11 workstation that is exhibiting severe performance degradation, frequent application crashes, and unusual network activity, even when no user applications are running. Initial antivirus scans come up clean. The technician suspects a sophisticated form of malware that is hiding its presence. Which type of malware is MOST likely responsible?

  1. AAdware
  2. BRootkit
  3. CWorm
  4. DSpyware
Show answer & explanation

Correct answer: B. Rootkit

A rootkit is designed to gain unauthorized access to a computer and often hides its presence, as well as the presence of other malicious software, making it difficult for standard antivirus scans to detect. Its characteristics align with severe performance issues and unusual network activity without obvious causes.

Why the other options are wrong

  • A. Adware primarily displays ads and redirects; it doesn't typically hide from antivirus scans in a sophisticated manner.
  • C. Worms self-replicate and spread, but their primary goal isn't to hide from the OS or antivirus, and they don't necessarily cause application crashes and unusual network activity without a clear payload.
  • D. Spyware focuses on data collection; while it can cause performance issues, its defining characteristic isn't hiding from the OS or antivirus in a 'sophisticated' manner.

Rootkit

A type of malicious software designed to gain unauthorized access to a computer or network and often hides its presence and the presence of other malware, making it difficult to detect.

  • Operates at a low level of the operating system.
  • Can modify system files and processes to conceal its activities.
  • Often difficult to detect with traditional antivirus software.

Memory trick: Rootkits dig deep to hide, like roots under a tree.

More Security questions