CompTIA Tech+ (FC0-U71)SecurityHard
A technician is installing a new antivirus solution on a corporate network. After installation, the antivirus software detects a file that attempts to modify the operating system's boot sector and remain hidden from detection. This behavior is characteristic of which type of malware?
- ARansomware
- BRootkit
- CAdware
- DSpyware
Show answer & explanationAnswer & explanation
Correct answer: B. Rootkit
A rootkit is a type of malware designed to gain unauthorized access to a computer and remain hidden, often by modifying core operating system components, including the boot sector, to evade detection. It aims to maintain persistent, privileged access.
Why the other options are wrong
- A. Ransomware encrypts data and demands a ransom for its decryption.
- C. Adware primarily displays unwanted advertisements.
- D. Spyware is designed to gather information about a user without their knowledge.
Rootkit
A stealthy type of malware designed to hide the existence of certain processes or programs from normal detection methods and enable persistent privileged access to a computer.
- Modifies core OS components (e.g., boot sector, kernel).
- Aims for persistent, hidden access.
- Difficult to detect and remove.
Memory trick: Malware: Viruses attack, Rootkits hide, Ransomware locks.