Which tool scans a system for rootkits - CompTIA Linux + XK0-005

Question

Which tool scans a system for rootkits?

Answers
  1. correct
Explanation

The Correct Answer is: A. chkrootkit
chkrootkit is a specialized tool used to scan a Linux system for rootkits—malicious programs designed to gain unauthorized root access while hiding their presence. It checks for known signatures and behaviors of rootkits by examining binaries and system files for signs of compromise.

Why the other options are incorrect:

  • B. firewall-cmd
    This tool is part of the firewalld suite used to manage firewall rules and network zones. It controls access to ports and services but does not scan for malware or rootkits. Its purpose is to manage traffic, not detect system infections.

  • C. lynis
    While lynis is a powerful security auditing tool, it provides a broader system analysis, such as checking for insecure settings, missing patches, and general hardening issues. Although it may alert on suspicious signs, it is not specifically focused on rootkit detection like chkrootkit.

  • D. auditctl
    This tool is part of the Linux audit system, used to configure auditing rules that monitor system activity. It helps log and track changes for security compliance but does not perform scans for malware or detect rootkits.

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered