exam questions

Exam 312-50v12 All Questions

View all questions & answers for the 312-50v12 exam

Exam 312-50v12 topic 1 question 314 discussion

Actual exam question from ECCouncil's 312-50v12
Question #: 314
Topic #: 1
[All 312-50v12 Questions]

To invisibly maintain access to a machine, an attacker utilizes a rootkit that sits undetected in the core components of the operating system. What is this type of rootkit an example of?

  • A. Firmware rootkit
  • B. Kernel rootkit
  • C. Hypervisor rootkit -
    C. Hardware rootkit
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
e020fdc
1 month, 1 week ago
Selected Answer: B
A. Firmware rootkit Resides in the firmware (e.g., BIOS, UEFI) of hardware components. It operates below the OS, not in the core OS components. B. Kernel rootkit Operates at the kernel level — the core of the operating system. This gives it high-level privileges, allowing it to hide files, processes, and system activities; intercept system calls and manipulate outputs; and maintain stealthy, persistent access to the compromised system. Because it integrates into the core components of the OS, it is very difficult to detect and remove. C. Hypervisor rootkit Runs beneath the operating system, on the virtualization layer (hypervisor). It controls the OS by intercepting hardware calls — more advanced and rare. D. Hardware rootkit Embedded in the actual hardware or device firmware, such as network cards or hard drives. It's even lower-level than firmware rootkits.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...