During a security investigation on a compromised server, an administrator suspects a rootkit has been installed to maintain stealthy persistence. Which TWO of the following indicators of compromise specifically signal the presence of a rootkit?
- Discrepancies between low-level kernel queries and user-space administrative process listingsCevap
- Interception and modification of system calls to conceal specific files and active network connectionsCevap
- CAutonomous network scanning traffic targeting vulnerable SMB services across adjacent subnets
- DConfiguration of host firewall rules to restrict inbound ICMP request traffic
Cevap
The correct indicators of a rootkit are discrepancies between low-level kernel queries and user-space process listings, as well as the interception and modification of system calls to conceal files and network connections.
Rootkits achieve stealth by replacing or modifying operating system components and hooking system call interfaces. This creates discrepancies between raw kernel state and user-space management utilities, hiding malicious files, processes, and active network connections from administrators.
Adım Adım Çözüm
Anahtar Kavram
Rootkit Indicators of Compromise and Kernel-Level Concealment
Tahmini Süre:1m 0s