nerdexam
GIAC

GCED · Question #40

GCED Question #40: Real Exam Question with Answer & Explanation

Sign in or unlock GCED to reveal the answer and full explanation for question #40. The question stem and answer options stay visible for context.

Question

You are responding to an incident involving a Windows server on your company's network. During the investigation you notice that the system downloaded and installed two files, iexplorer.exe and iexplorer.sys. Based on the behavior of the system you suspect that these files are part of a rootkit. If this is the case what is the likely purpose of the .sys file?

Options

  • AIt is a configuration file used to open a backdoor
  • BIt is a logfile used to collect usernames and passwords
  • CIt is a device driver used to load the rootkit
  • DIt is an executable used to configure a keylogger

Unlock GCED to see the answer

You've previewed enough free GCED questions. Unlock GCED for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full GCED Practice