312-49v10 Exam QuestionsBrowse all questions from this exam

312-49v10 Exam - Question 380


Which of these rootkit detection techniques function by comparing a snapshot of the file system, boot records, or memory with a known and trusted baseline?

Show Answer
Correct Answer: B

Integrity-Based Detection functions by comparing a snapshot of the file system, boot records, or memory with a known and trusted baseline. This method looks for discrepancies between the current system state and the baseline, which could indicate the presence of a rootkit or other malicious activity.

Discussion

1 comment
Sign in to comment
ElbOption: B
Jun 6, 2024

Integrity-based detection functions by comparing a current file system, boot records, or memory snapshot with the trusted baseline. They notify the evidence or presence of malicious activity based on the dissimilarities between the current and baseline snapshots.