Study. uk . com
  1. Home
  2. All questions
  3. Question 475

CompTIA Security+ study material · question 475 of 611

Why should a suspected rootkit infection not be investigated using tools running on the affected host?

  1. The host's logs are encrypted
  2. The tools would overwrite volatile memory
  3. The tools require administrative privileges
  4. A rootkit subverts the operating system's reporting, so the host cannot be trusted to report on itself
Show the answer

Answer: D. A rootkit subverts the operating system's reporting, so the host cannot be trusted to report on itself

Analysis needs an external view, such as offline imaging or a known-good boot environment.

Challenge yourself on this topic → Study as cards