II0-001 · Question #217
Which of the following keymappers are the most difficult to detect by the subject of the monitoring?
The correct answer is A. Hardware keymapper. Hardware keymappers operate at the physical layer - inserted between a keyboard and a computer, or embedded in hardware - meaning they are completely invisible to the operating system and any software-based security tools (antivirus, EDR, process monitors). Because detection…
Question
Which of the following keymappers are the most difficult to detect by the subject of the monitoring?
Options
- AHardware keymapper
- BStealthMap
- CShadowCopy
- DNSA's HAL9000.09 Signaling Mirror
How the community answered
(58 responses)- A79% (46)
- B3% (2)
- C7% (4)
- D10% (6)
Explanation
Hardware keymappers operate at the physical layer - inserted between a keyboard and a computer, or embedded in hardware - meaning they are completely invisible to the operating system and any software-based security tools (antivirus, EDR, process monitors). Because detection software runs above the hardware layer, it has no visibility into a device that silently captures keystrokes before they ever reach the OS. Options B (StealthMap) and C (ShadowCopy) are fabricated names - StealthMap is not a recognized keymapper category, and ShadowCopy refers to Windows Volume Shadow Copy, a backup feature unrelated to keylogging. Option D (NSA's HAL9000.09 Signaling Mirror) is entirely fictional. Memory tip: Think "hardware hides hardest" - if it plugs in physically, software can't see it, making hardware-based keyloggers the stealthiest option on any exam covering monitoring and detection evasion.
Community Discussion
No community discussion yet for this question.