GCIH Exam QuestionsBrowse all questions from this exam

GCIH Exam - Question 30


Which of the following tools uses common UNIX/Linux tools like the strings and grep commands to search core system programs for signatures of the rootkits?

Show Answer
Correct Answer: C

Chkrootkit (Check Rootkit) is a Unix-based utility that aids in examining systems for rootkits by using common Unix/Linux tools like the strings and grep commands. It scans core system programs to identify signatures of rootkits, making it the correct answer.

Discussion

2 comments
Sign in to comment
anonyuserOption: A
Jan 29, 2024

openai thinks this is a

straleOption: C
Feb 15, 2024

From wikipedia: Chkrootkit (Check Rootkit) is a widely used Unix-based utility designed to aid system administrators in examining their systems for rootkits. Operating as a shell script, it leverages common Unix/Linux tools such as the strings and grep command. The primary purpose is to scan core system programs for identifying signatures and to compare data obtained from traversal the /proc with the output derived from the ps (process status) command, aiming to identify inconsistencies. This is exactly what the question is asking, I am going for C