CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

During an incident response, a security team discovers that a compromised Linux server's kernel-level components have been modified to hide malicious processes and network connections from standard system utilities. Which type of malware is most likely responsible?

  1. AWorm
  2. BLogic bomb
  3. CAdware
  4. DRootkit
Show answer & explanation

Correct answer: D. Rootkit

A rootkit modifies the operating system at a low level, often the kernel, to conceal malicious processes, files, and connections from detection tools. This gives attackers persistent, stealthy access to the compromised system.

Why the other options are wrong

  • A. A worm self-replicates across networks but does not inherently hide itself at the kernel level.
  • B. A logic bomb triggers malicious action based on a condition or time, not stealth via kernel modification.
  • C. Adware displays unwanted advertisements and is not designed for stealthy kernel-level concealment.

Rootkit

Malware that gains and maintains privileged access to a system while hiding its presence, often by modifying the OS kernel or core utilities.

  • Operates at kernel or firmware level for stealth
  • Difficult to detect with standard OS tools
  • Often requires specialized detection or full OS reinstall to remove

Memory trick: Rootkit digs to the 'root' of the OS to become invisible.

More Threats, Vulnerabilities, and Mitigations questions