hardMultiple Select
XK0-006 Practice Question: Which TWO tools are specifically designed to…
Which TWO tools are specifically designed to detect rootkits on a Linux system?
⚠ Common exam trap
Many candidates confuse general system monitoring tools (lsof, netstat) or general antivirus (ClamAV) with specialized rootkit detection tools, but only rkhunter and chkrootkit are explicitly designed for that purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
rkhunter
rkhunter (B) is a dedicated rootkit hunter that scans for known rootkit signatures, suspicious files, and hidden processes on Linux, making it specifically designed for rootkit detection. chkrootkit (E) is likewise a purpose-built tool that checks system binaries and common rootkit infection vectors on Linux. By contrast, lsof (A) only lists open files and associated processes, netstat (C) merely displays network connections and routing tables, and clamav (D) is an antivirus scanner targeting malware such as viruses and trojans rather than rootkits specifically, so none of these are specifically designed for rootkit detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
lsof
Why it's wrong here
lsof lists open files and the processes holding them; it does not scan for rootkit binaries or kernel modifications. It tempts because hidden file handles can hint at compromise, but that is forensic guesswork — lsof would be correct for diagnosing file locks or open descriptors, not rootkit detection.
- ✓
rkhunter
Why this is correct
rkhunter scans for rootkit signatures, comparing file hashes and permissions against known-good databases to flag hidden binaries, suspicious kernel modules and altered system files. This satisfies the stem's requirement for a tool specifically designed for rootkit detection, rather than general malware or vulnerability scanning.
- ✗
netstat
Why it's wrong here
netstat reports network connections, routing tables, and interface statistics; it performs no rootkit detection. It tempts because rootkits often hide listening ports, so administrators inspect sockets, but that is manual investigation — netstat would be correct for connection troubleshooting, not rootkit scanning.
- ✗
clamav
Why it's wrong here
ClamAV is an antivirus scanner targeting malware and viruses in files and mail, not rootkit-specific integrity checking. It tempts because it is a well-known Linux security tool, and would be the right choice for malware or email gateway scanning, not for detecting hidden kernel-level rootkit components.
- ✓
chkrootkit
Why this is correct
chkrootkit scans for known rootkit signatures by comparing system binaries against trusted versions and inspecting common infection vectors such as altered `ps`, `ls` and network interfaces. It directly satisfies the stem's requirement for a tool specifically designed to detect rootkits on Linux, rather than general malware or vulnerability scanning.
Go deeper
Related to this question
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.