Courseiva

CEH Enumeration and System Hacking Practice Question

Which THREE of the following are indicators that a system has been compromised by a rootkit? (Select 3)

⚠ Common exam trap

A common mix-up: candidates confuse rootkit indicators with general malware symptoms, such as repeated login failures (D) or disk space changes (E), but rootkits specifically focus on stealth and hiding their presence, not generating obvious anomalies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Anti-virus software is disabled and cannot be restarted

Option A is correct because rootkits commonly disable or interfere with security tools such as anti-virus software, and the inability to restart them is a strong indicator of kernel-level or user-mode tampering. Option B is correct because rootkits are specifically designed to hide their presence, often by hooking system calls or modifying kernel structures so that processes, files, or registry keys do not appear in standard tools like Task Manager, ps, or top. Option C is correct because rootkits frequently maintain persistence and remote control by establishing covert connections to command-and-control (C2) servers, and such unexplained outbound traffic is a classic sign of compromise. Option D is not correct because repeated successful logins from unknown IPs suggest credential compromise or brute-force success, but they do not specifically indicate a rootkit, which is characterized by stealth and system-level hiding. Option E is not correct because increased disk space usage is a generic symptom that can result from many benign causes such as log growth, updates, or user data, and is not a specific indicator of rootkit activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Anti-virus software is disabled and cannot be restarted

    Why this is correct

    Rootkits frequently operate at a low level within the operating system, often in kernel mode, enabling them to interfere directly with security software processes, hooks, and drivers. When anti-virus software is persistently disabled and cannot be restarted, it is a strong indicator that a sophisticated threat, like a rootkit, is actively subverting the system's defenses. This behavior aims to neutralize detection mechanisms and maintain stealth, making the compromise difficult to remediate.

  • ✓

    Hidden processes that do not appear in process lists

    Why this is correct

    Rootkits achieve process hiding by manipulating kernel-level data structures, such as linked lists of processes, or by hooking critical API calls that enumeration tools rely upon (e.g., NtQuerySystemInformation on Windows). This manipulation ensures that malicious processes, threads, or modules are omitted from standard task managers or 'ps' commands. The presence of hidden processes, undetectable by conventional system monitoring tools, is a hallmark of a rootkit's stealth capabilities.

  • ✓

    Unexplained network connections to known command-and-control servers

    Why this is correct

    Rootkits commonly establish covert network connections to command-and-control (C2) servers to receive instructions, exfiltrate sensitive data, or download additional malicious payloads. While other malware also utilizes C2, a rootkit's ability to hide its network activity by manipulating network stack APIs makes these unexplained connections particularly indicative of a deep system compromise. Such connections, especially to known malicious infrastructure, signify an active and controlled threat.

  • ✗

    Event logs show repeated successful logins from unknown IPs

    Why it's wrong here

    Repeated successful logins from unknown IP addresses primarily indicate a compromised user account, likely due to credential theft, brute-force attacks, or password reuse. While a system with a rootkit might also exhibit this symptom, it is not a direct or specific indicator of a rootkit's presence itself. This symptom points more directly to unauthorized access via legitimate credentials rather than the stealthy, low-level presence of a rootkit.

  • ✗

    Increased disk space usage without explanation

    Why it's wrong here

    An unexplained increase in disk space usage is a very general symptom that can result from numerous legitimate activities, such as large software updates, temporary file accumulation, or user data storage. While some malware might consume disk space, rootkits are specifically designed for stealth and often have a minimal footprint to avoid detection. Therefore, this symptom is too broad and non-specific to be a reliable indicator of a rootkit's presence.

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.