Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingHard

During the eradication phase of a malware incident, a security engineer discovers a sophisticated rootkit embedded deep within the operating system of several critical servers. Traditional antivirus and anti-malware tools have failed to remove it completely, and simply deleting files has proven ineffective due to persistence mechanisms. What is the MOST secure and reliable method to ensure complete eradication of this type of persistent threat?

  1. APerform a full re-image of the compromised servers from trusted media.
  2. BManually delete identified rootkit files and registry entries from safe mode.
  3. CApply a signature-based antivirus update and rescan all affected systems.
  4. DIsolate the servers and monitor them for a few days to see if the rootkit reactivates.
Show answer & explanation

Correct answer: A. Perform a full re-image of the compromised servers from trusted media.

For sophisticated and persistent threats like rootkits that resist traditional removal methods, a full re-image from trusted media is the most secure and reliable way to ensure complete eradication, as it replaces the entire operating system and all applications with a clean version.

Why the other options are wrong

  • B. Manual deletion is risky and often incomplete for sophisticated rootkits that can hide or re-establish themselves.
  • C. Signature-based updates may not catch sophisticated rootkits, especially if they are polymorphic or zero-day.
  • D. Monitoring in isolation does not eradicate the threat; it only delays action.

Rootkit Eradication

The challenging process of completely removing deeply embedded and persistent malware (rootkits) from a compromised system.

  • Rootkits hide their presence and often survive reboots.
  • Traditional AV/AM tools may not detect or remove them fully.
  • Full system re-imaging is often the most reliable eradication method.

Memory trick: When the pest is too deep, you must rebuild the whole house.

More Incident Handling questions