220-1002 · Question #720
Which of the following malware types would MOST likely require reimaging?
The correct answer is C. Rootkit. Rootkits embed themselves at the kernel or boot level, making them resistant to standard removal tools and typically requiring a full reimage to guarantee remediation.
Question
Which of the following malware types would MOST likely require reimaging?
Options
- ABotnet
- BSpyware
- CRootkit
- DKeylogger
How the community answered
(55 responses)- A2% (1)
- B4% (2)
- C89% (49)
- D5% (3)
Why each option
Rootkits embed themselves at the kernel or boot level, making them resistant to standard removal tools and typically requiring a full reimage to guarantee remediation.
Botnets are network-based malware that can typically be disconnected and removed with endpoint security tools without requiring a full reimage.
Spyware operates at the application layer and can generally be detected and removed by anti-spyware or antivirus software without reimaging.
Rootkits operate below the operating system layer, hooking into the kernel or bootloader to hide their presence and persist across reboots. Because they compromise the integrity of the OS itself, antivirus tools running within that OS cannot reliably detect or remove all traces. Reimaging the machine is the only way to ensure the system is fully clean.
Keyloggers are application-layer threats that standard antivirus and anti-malware tools can usually detect and remove without needing a reimage.
Concept tested: Rootkit remediation and reimaging requirement
Source: https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/rootkits-malware
Topics
Community Discussion
No community discussion yet for this question.