GIAC
GCED · Question #40
You are responding to an incident involving a Windows server on your company's network. During the investigation you notice that the system downloaded and installed two files, iexplorer.exe and…
The correct answer is C. It is a device driver used to load the rootkit. You've hit your limit · resets 1pm (America/New_York)
Host Security and Management
Question
You are responding to an incident involving a Windows server on your company's network. During the investigation you notice that the system downloaded and installed two files, iexplorer.exe and iexplorer.sys. Based on the behavior of the system you suspect that these files are part of a rootkit. If this is the case what is the likely purpose of the .sys file?
Options
- AIt is a configuration file used to open a backdoor
- BIt is a logfile used to collect usernames and passwords
- CIt is a device driver used to load the rootkit
- DIt is an executable used to configure a keylogger
How the community answered
(24 responses)- A4% (1)
- C96% (23)
Explanation
You've hit your limit · resets 1pm (America/New_York)
Topics
#rootkit#device driver#malware analysis#Windows kernel
Community Discussion
No community discussion yet for this question.