🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

While investigating unusual outbound traffic, you discover that an Amazon EC2 Linux instance contains a loadable kernel module that is invisible to lsmod and persists across reboots. You suspect a rootkit is present. Which remediation approach best aligns with industry practice for removing this type of malware without depending on system tools that may already be compromised?

  • Install the latest kernel packages on the running instance and reboot to overwrite the malicious module.

  • Enable Amazon GuardDuty and wait for a finding, then quarantine the instance.

  • Reinstall the lsmod utility with the package manager and rerun it until the hidden module becomes visible.

  • Stop the instance, attach its volume to a clean rescue host, and run a file-integrity scan built from a trusted baseline before restoring or rebuilding the system.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot