nerdexam
IISFA

II0-001 · Question #217

Which of the following keymappers are the most difficult to detect by the subject of the monitoring?

The correct answer is A. Hardware keymapper. Hardware keymappers operate at the physical layer - inserted between a keyboard and a computer, or embedded in hardware - meaning they are completely invisible to the operating system and any software-based security tools (antivirus, EDR, process monitors). Because detection…

Question

Which of the following keymappers are the most difficult to detect by the subject of the monitoring?

Options

  • AHardware keymapper
  • BStealthMap
  • CShadowCopy
  • DNSA's HAL9000.09 Signaling Mirror

How the community answered

(58 responses)
  • A
    79% (46)
  • B
    3% (2)
  • C
    7% (4)
  • D
    10% (6)

Explanation

Hardware keymappers operate at the physical layer - inserted between a keyboard and a computer, or embedded in hardware - meaning they are completely invisible to the operating system and any software-based security tools (antivirus, EDR, process monitors). Because detection software runs above the hardware layer, it has no visibility into a device that silently captures keystrokes before they ever reach the OS. Options B (StealthMap) and C (ShadowCopy) are fabricated names - StealthMap is not a recognized keymapper category, and ShadowCopy refers to Windows Volume Shadow Copy, a backup feature unrelated to keylogging. Option D (NSA's HAL9000.09 Signaling Mirror) is entirely fictional. Memory tip: Think "hardware hides hardest" - if it plugs in physically, software can't see it, making hardware-based keyloggers the stealthiest option on any exam covering monitoring and detection evasion.

Community Discussion

No community discussion yet for this question.

Full II0-001 Practice