CompTIA Tech+ (FC0-U71)SecurityHard
A security analyst is investigating a suspected malware infection where a user's computer is behaving erratically, background processes are consuming excessive resources, and the antivirus software is unable to detect or remove the threat. Further analysis reveals that the malicious software is deeply embedded within the operating system kernel and is hiding its presence from detection tools. What type of malware is most likely responsible for this compromise?
- AAdware
- BRansomware
- CRootkit
- DSpyware
Show answer & explanationAnswer & explanation
Correct answer: C. Rootkit
A rootkit is a type of malicious software designed to gain root-level or administrative access to a computer and hide its presence, as well as the presence of other malicious software. Its ability to embed within the OS kernel and evade detection by antivirus software perfectly matches the scenario described.
Why the other options are wrong
- A. Adware primarily displays unwanted advertisements and does not typically embed itself deeply in the OS kernel to hide from antivirus.
- B. Ransomware encrypts data and demands a ransom, but its primary characteristic isn't hiding deep within the kernel to evade detection like a rootkit.
- D. Spyware collects user information but doesn't necessarily hide itself at the kernel level or evade antivirus in the manner described.
Rootkit
A malicious software package designed to gain unauthorized root-level or administrative access to a computer system and hide its presence from detection.
- Operates at a low level within the operating system (e.g., kernel).
- Can hide processes, files, and network connections.
- Extremely difficult to detect and remove with standard antivirus tools.
Memory trick: Rootkits hide, ransomware encrypts, worms spread.