Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium

An attacker successfully compromises a web server and installs a rootkit. Which characteristic of a rootkit makes it particularly dangerous for maintaining covert access and avoiding detection?

  1. AIt encrypts all data on the compromised system, demanding a ransom.
  2. BIt modifies core operating system files to hide its presence and malicious activities.
  3. CIt spreads rapidly across the network by exploiting unpatched client vulnerabilities.
  4. DIt performs denial-of-service attacks by flooding network resources.
Show answer & explanation

Correct answer: B. It modifies core operating system files to hide its presence and malicious activities.

Rootkits are designed to gain root-level access and then modify core operating system functions to hide their own presence, as well as the presence of other malicious software or activities. This stealth capability makes them very effective for maintaining covert, persistent access.

Why the other options are wrong

  • A. This describes ransomware, not a rootkit.
  • C. This describes a worm, which focuses on rapid self-propagation, not primarily stealthy hiding.
  • D. This describes a DDoS attack tool, not the primary function of a rootkit.

Rootkit

A collection of malicious software designed to enable access to a computer or an area of its software that is not otherwise allowed (for example, to an unauthorized user) and often masks its existence or the existence of other malware.

  • Gains root/administrative access.
  • Modifies OS kernel/system files.
  • Hides its own presence and other malicious activities.
  • Difficult to detect and remove.

Memory trick: Malware has many forms: Rootkits hide, Ransomware locks, Worms spread, Trojans trick.

More Cybersecurity Fundamentals questions