220-802 · Question #952
After gaining administrative access, a malicious intruder might leave which of the following behind on a compromised system to allow for continued monitoring and access?
The correct answer is D. Rootkit. A rootkit is specifically designed to maintain persistent, hidden administrative access to a compromised system. It operates at a low level (kernel or firmware) to conceal its presence from the OS, antivirus tools, and administrators, allowing the attacker to return undetected…
Question
After gaining administrative access, a malicious intruder might leave which of the following behind on a compromised system to allow for continued monitoring and access?
Options
- ATrojan horse
- BLogic bomb
- CSpyware
- DRootkit
How the community answered
(47 responses)- A4% (2)
- B4% (2)
- C2% (1)
- D89% (42)
Explanation
A rootkit is specifically designed to maintain persistent, hidden administrative access to a compromised system. It operates at a low level (kernel or firmware) to conceal its presence from the OS, antivirus tools, and administrators, allowing the attacker to return undetected. A Trojan horse is an initial delivery mechanism, not a persistence tool. A logic bomb executes a destructive payload when triggered - it does not provide ongoing access. Spyware collects data but does not specifically provide the attacker with remote administrative control or hide itself as thoroughly as a rootkit.
Topics
Community Discussion
No community discussion yet for this question.