Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesHard

A company is conducting a forensic investigation after a server was compromised. The investigators find that the attacker modified system logs to hide their activities and installed a backdoor that replaces legitimate system binaries with malicious versions. Which type of malware is the attacker most likely using to achieve these goals?

  1. ATrojan
  2. BSpyware
  3. CRootkit
  4. DWorm
Show answer & explanation

Correct answer: C. Rootkit

The ability to modify system logs to hide activities and replace legitimate system binaries with malicious versions are classic characteristics of a rootkit. Rootkits are designed to provide persistent, stealthy access and hide their presence.

Why the other options are wrong

  • A. Trojans disguise themselves as legitimate software but don't inherently possess the stealth capabilities of a rootkit to modify system internals and hide.
  • B. Spyware collects information about a user's activities without their knowledge, which is distinct from hiding an attacker's presence and maintaining access.
  • D. Worms are self-replicating malware that spread across networks, not primarily focused on hiding activities on a compromised host.

Rootkit

A collection of malicious software tools designed to enable administrator-level access to a computer or network while simultaneously attempting to hide its presence from legitimate users and security software. Rootkits often modify core operating system components.

  • Provides stealthy, persistent, privileged access.
  • Can hide processes, files, network connections, and modify logs.
  • Extremely difficult to detect and remove without reinstalling the OS.

Memory trick: Stealth malware: Rootkit hides deep, Trojan pretends, Worm spreads.

More Security Principles questions