Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringHard
A security analyst is reviewing a SIEM dashboard and observes a series of alerts indicating 'Unauthorized modification of system binaries' on multiple Linux servers. Further investigation reveals that the 'ls' and 'ps' commands are reporting inaccurate information, and some running processes are not visible through standard tools. What type of malicious software is most likely at play?
- ASpyware
- BRansomware
- CRootkit
- DAdware
Show answer & explanationAnswer & explanation
Correct answer: C. Rootkit
The scenario describes unauthorized modification of system binaries ('ls', 'ps' reporting inaccurate info) and the hiding of running processes. These are classic characteristics of a rootkit, which aims to maintain stealthy, persistent access by subverting operating system functions.
Why the other options are wrong
- A. Spyware collects information but doesn't typically modify system binaries or hide processes.
- B. Ransomware encrypts files and demands a ransom, it doesn't typically focus on hiding system binaries or processes in this manner.
- D. Adware displays unwanted advertisements and does not involve hiding processes or modifying system binaries.
Rootkit Characteristics
A rootkit is a collection of malicious software designed to enable access to a computer or an area of its software that is not otherwise allowed and often masks its existence or the existence of other malware.
- Hides processes, files, network connections, and registry keys.
- Modifies core OS components or kernel modules.
- Subverts standard system utilities (e.g., 'ls', 'ps') to provide false information.
- Difficult to detect and remove, often requiring specialized tools or OS reinstallation.
Memory trick: Malware types are like different criminal roles, each with a specific modus operandi.