nerdexam
EC-Council

212-82 · Question #154

An international bank recently discovered a security breach in its transaction processing system. The breach involved a sophisticated malware that not only bypassed the standard antivirus software…

The correct answer is D. embedding itself deeply in the system to manipulate transaction processes. Rootkit Malware in Financial Systems Option D correctly describes a rootkit, which is malware designed to embed itself deeply within a system's core processes (often at the kernel level), granting it persistent, hidden access while manipulating system functions - in this case…

Submitted by tunde_lagos· Mar 6, 2026Application Security for Cloud

Question

An international bank recently discovered a security breach in its transaction processing system. The breach involved a sophisticated malware that not only bypassed the standard antivirus software but also remained undetected by the intrusion detection systems for months. The malware was programmed to intermittently alter transaction values and transfer small amounts to a foreign account, making detection challenging due to the subtlety of its actions. After a thorough investigation, cybersecurity experts identified the nature of this malware. Which of the following best describes the type of malware used in this breach?

Options

  • ARansomware, encrypting transaction data to extort money from the bank
  • Bpresenting itself as legitimate software while performing malicious transactions
  • CSpyware, gathering sensitive information about the bank's transactions and customers Rootki'
  • Dembedding itself deeply in the system to manipulate transaction processes

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    14% (3)
  • C
    5% (1)
  • D
    77% (17)

Explanation

Rootkit Malware in Financial Systems

Option D correctly describes a rootkit, which is malware designed to embed itself deeply within a system's core processes (often at the kernel level), granting it persistent, hidden access while manipulating system functions - in this case, quietly altering transaction values over months without detection. Rootkits are specifically engineered to evade antivirus and intrusion detection systems by operating below the visibility of standard security tools, perfectly matching the scenario described.

Why the distractors are wrong:

  • Option A (Ransomware) is incorrect because ransomware encrypts data and demands payment - it is loud and disruptive by design, not subtle and long-term
  • Option B (Trojan) is incorrect because while Trojans disguise themselves as legitimate software, they don't specifically explain the deep system embedding and long-term undetectability described
  • Option C (Spyware) is incorrect because spyware collects and transmits information passively - it doesn't actively alter transaction values or manipulate processes

Memory Tip: Think of a rootkit as a "ghost in the basement" - it hides in the deepest part of the system (the "root"), stays invisible for a long time, and silently manipulates things from below. If the scenario emphasizes long-term stealth + system manipulation, think rootkit.

Topics

#Malware Analysis#Rootkits#Application Attacks#Cybersecurity Threats

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice