Courseiva
hardMultiple Select

XK0-006 Practice Question: Which TWO tools are specifically designed to…

Which TWO tools are specifically designed to detect rootkits on a Linux system?

⚠ Common exam trap

Many candidates confuse general system monitoring tools (lsof, netstat) or general antivirus (ClamAV) with specialized rootkit detection tools, but only rkhunter and chkrootkit are explicitly designed for that purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

rkhunter

rkhunter (B) is a dedicated rootkit hunter that scans for known rootkit signatures, suspicious files, and hidden processes on Linux, making it specifically designed for rootkit detection. chkrootkit (E) is likewise a purpose-built tool that checks system binaries and common rootkit infection vectors on Linux. By contrast, lsof (A) only lists open files and associated processes, netstat (C) merely displays network connections and routing tables, and clamav (D) is an antivirus scanner targeting malware such as viruses and trojans rather than rootkits specifically, so none of these are specifically designed for rootkit detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    lsof

    Why it's wrong here

    lsof lists open files and the processes holding them; it does not scan for rootkit binaries or kernel modifications. It tempts because hidden file handles can hint at compromise, but that is forensic guesswork — lsof would be correct for diagnosing file locks or open descriptors, not rootkit detection.

  • ✓

    rkhunter

    Why this is correct

    rkhunter scans for rootkit signatures, comparing file hashes and permissions against known-good databases to flag hidden binaries, suspicious kernel modules and altered system files. This satisfies the stem's requirement for a tool specifically designed for rootkit detection, rather than general malware or vulnerability scanning.

  • ✗

    netstat

    Why it's wrong here

    netstat reports network connections, routing tables, and interface statistics; it performs no rootkit detection. It tempts because rootkits often hide listening ports, so administrators inspect sockets, but that is manual investigation — netstat would be correct for connection troubleshooting, not rootkit scanning.

  • ✗

    clamav

    Why it's wrong here

    ClamAV is an antivirus scanner targeting malware and viruses in files and mail, not rootkit-specific integrity checking. It tempts because it is a well-known Linux security tool, and would be the right choice for malware or email gateway scanning, not for detecting hidden kernel-level rootkit components.

  • ✓

    chkrootkit

    Why this is correct

    chkrootkit scans for known rootkit signatures by comparing system binaries against trusted versions and inspecting common infection vectors such as altered `ps`, `ls` and network interfaces. It directly satisfies the stem's requirement for a tool specifically designed to detect rootkits on Linux, rather than general malware or vulnerability scanning.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.