CompTIA Tech+ (FC0-U71)SecurityMedium
A system administrator is investigating a user's computer that is exhibiting unusual behavior, including unexpected system reboots, disabled security software, and an inability to run certain diagnostic tools. The administrator suspects a sophisticated, stealthy form of malware. Which type of malware is most likely causing these symptoms?
- ASpyware
- BRootkit
- CAdware
- DRansomware
Show answer & explanationAnswer & explanation
Correct answer: B. Rootkit
Rootkits are designed to gain unauthorized access to a computer and hide their presence, often by modifying operating system processes or disabling security software, leading to the observed symptoms of stealthy control and interference with diagnostics.
Why the other options are wrong
- A. Spyware collects user data secretly but usually doesn't involve system reboots or disabling security tools to hide itself at such a deep level.
- C. Adware primarily displays unwanted advertisements and does not typically disable security software or cause reboots.
- D. Ransomware encrypts files and demands payment, with its presence being very obvious, not stealthy.
Rootkit
A type of malicious software designed to gain control over a computer system without being detected, often by modifying core operating system files.
- Hides its presence and other malware.
- Can disable security software.
- Operates at a deep system level (kernel or user mode).
Memory trick: When the system acts like a ghost, a Rootkit's the host.