Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium

A cybersecurity analyst is investigating a report of a compromised web server. They discover that an attacker exploited a vulnerability in the server's operating system, gained root access, and installed a hidden program that allows persistent remote access while actively concealing its presence from common system utilities. What type of malware has most likely been installed?

  1. ASpyware
  2. BAdware
  3. CRootkit
  4. DRansomware
Show answer & explanation

Correct answer: C. Rootkit

A rootkit is a collection of malicious tools designed to obtain and maintain root-level access to a computer system while actively hiding its presence from system administrators and security software. The description of gaining root access, installing a hidden program, and concealing its presence directly matches a rootkit.

Why the other options are wrong

  • A. Spyware collects information about a user without their knowledge, not typically focused on root access or hiding from utilities in this manner.
  • B. Adware displays unwanted advertisements, not focused on hiding or root access.
  • D. Ransomware encrypts data and demands payment, not primarily focused on covert persistence.

Rootkit

A type of malicious software designed to hide its presence and activity on a computer system while providing privileged, persistent access to an attacker.

  • Operates at a low level (kernel or user mode).
  • Can modify operating system files or kernel modules.
  • Difficult to detect and remove with standard tools.

Memory trick: Malware: Viruses, Worms, Trojans, Ransom, Rootkits, Spyware, Adware

More Security Principles questions