ITPEC FE Subject A April 2024 Question 28
ITPEC FE Subject A April 2024 — Question 28 of 60
Rootkit — malware toolkit that creates backdoors and hides evidence of intrusion.
A rootkit is a collection of malicious programs installed after unauthorized access to a system. It typically:
- Opens a backdoor for persistent remote access
- Hides processes, files, and logs to conceal the intrusion
- Operates at a privileged (root/admin) level
Why not others:
- (a) RFID — radio-frequency identification technology; used for contactless tags/cards, unrelated to intrusion
- (c) TKIP — Temporal Key Integrity Protocol; a Wi-Fi encryption protocol (used in WPA), not malware
- (d) Web beacon — a tiny invisible image (1×1 px) embedded in emails/pages to track opens; not an intrusion toolkit
Key rule: Rootkit = backdoor + hide traces. The name comes from "root" (superuser) + "kit" (toolkit).
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.