ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
While monitoring a Linux Amazon EC2 instance that runs an internal web app, the security team sees a spike in outbound traffic to unknown IPs. Standard utilities like ps and netstat show nothing unusual. Systems Manager Inventory then reports unauthorized kernel modules and that /bin/ls and /usr/bin/ps have been altered. Which malware type is most likely responsible?
Crypto-ransomware encrypting user files and displaying ransom notes
A kernel-mode rootkit that hides its presence by modifying system calls and core binaries
A self-propagating network worm exploiting SMB vulnerabilities
A trojanized remote-access tool installed through phishing
The symptoms point to stealth techniques that operate in kernel space and tamper with core binaries so that normal commands hide files, processes, and network sockets. That behavior is characteristic of a kernel-mode rootkit. Worms focus on rapid propagation and are usually visible in process or socket lists, ransomware announces itself with ransom notes, and typical phishing-delivered RATs stay in user space without replacing kernel modules or system binaries.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a kernel-mode rootkit?
Open an interactive chat with Bash
Why were standard tools like ps and netstat ineffective in detecting the malware?
Open an interactive chat with Bash
What is Systems Manager Inventory and how does it help detect security issues?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .