Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium
A cybersecurity analyst is investigating a report of a compromised web server. They discover that an attacker exploited a vulnerability in the server's operating system, gained root access, and installed a hidden program that allows persistent remote access while actively concealing its presence from common system utilities. What type of malware has most likely been installed?
- ASpyware
- BAdware
- CRootkit
- DRansomware
Show answer & explanationAnswer & explanation
Correct answer: C. Rootkit
A rootkit is a collection of malicious tools designed to obtain and maintain root-level access to a computer system while actively hiding its presence from system administrators and security software. The description of gaining root access, installing a hidden program, and concealing its presence directly matches a rootkit.
Why the other options are wrong
- A. Spyware collects information about a user without their knowledge, not typically focused on root access or hiding from utilities in this manner.
- B. Adware displays unwanted advertisements, not focused on hiding or root access.
- D. Ransomware encrypts data and demands payment, not primarily focused on covert persistence.
Rootkit
A type of malicious software designed to hide its presence and activity on a computer system while providing privileged, persistent access to an attacker.
- Operates at a low level (kernel or user mode).
- Can modify operating system files or kernel modules.
- Difficult to detect and remove with standard tools.
Memory trick: Malware: Viruses, Worms, Trojans, Ransom, Rootkits, Spyware, Adware