Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesHard
A company is conducting a forensic investigation after a server was compromised. The investigators find that the attacker modified system logs to hide their activities and installed a backdoor that replaces legitimate system binaries with malicious versions. Which type of malware is the attacker most likely using to achieve these goals?
- ATrojan
- BSpyware
- CRootkit
- DWorm
Show answer & explanationAnswer & explanation
Correct answer: C. Rootkit
The ability to modify system logs to hide activities and replace legitimate system binaries with malicious versions are classic characteristics of a rootkit. Rootkits are designed to provide persistent, stealthy access and hide their presence.
Why the other options are wrong
- A. Trojans disguise themselves as legitimate software but don't inherently possess the stealth capabilities of a rootkit to modify system internals and hide.
- B. Spyware collects information about a user's activities without their knowledge, which is distinct from hiding an attacker's presence and maintaining access.
- D. Worms are self-replicating malware that spread across networks, not primarily focused on hiding activities on a compromised host.
Rootkit
A collection of malicious software tools designed to enable administrator-level access to a computer or network while simultaneously attempting to hide its presence from legitimate users and security software. Rootkits often modify core operating system components.
- Provides stealthy, persistent, privileged access.
- Can hide processes, files, network connections, and modify logs.
- Extremely difficult to detect and remove without reinstalling the OS.
Memory trick: Stealth malware: Rootkit hides deep, Trojan pretends, Worm spreads.