CHFI OS and Network Forensics Practice Question
An analyst is reviewing a Linux system for signs of a rootkit. Which THREE of the following are common indicators of a rootkit infection? (Select THREE.)
⚠ Common exam trap
EC-Council often tests the distinction between network-based attack indicators (like failed SSH logins) and host-based rootkit artifacts (like /proc anomalies or modified binaries), leading candidates to confuse brute-force activity with kernel-level compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anomalies in the /proc filesystem
Option B is correct because a rootkit often hooks or hides processes, files, and network sockets by tampering with the kernel's virtual /proc filesystem, so discrepancies between /proc entries and tools like ps or ls, or missing PIDs, are a classic anomaly. Option D is correct because rootkits frequently install malicious loadable kernel modules (LKMs) to intercept syscalls and conceal their presence, so unexpected or unsigned modules in lsmod//proc/modules are a strong indicator. Option E is correct because rootkits commonly replace or trojanize core system binaries such as ls, ps, netstat, and top so they omit the attacker's processes and files, which can be detected via package verification (rpm -V, debsums) or checksum comparison. Option A is not a typical rootkit indicator, since incorrect permissions on /etc/passwd usually reflect misconfiguration or a separate privilege/account issue rather than kernel-level concealment. Option C is also not specific to rootkits, as a high volume of failed SSH logins indicates brute-force or credential-stuffing attempts, not the stealth mechanisms a rootkit employs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Incorrect file permissions on /etc/passwd
Why it's wrong here
Incorrect permissions on /etc/passwd, such as world-writable settings, are a serious system integrity flaw and may indicate misconfiguration or a local privilege escalation attempt, but they are not a characteristic rootkit artifact. Rootkits achieve stealth by intercepting kernel calls or replacing system binaries rather than by leaving obvious file-permission changes that would be flagged by basic auditing. Furthermore, modern Linux systems store password hashes in /etc/shadow, making /etc/passwd less sensitive, so while the change warrants investigation, it does not specifically point to a rootkit infection.
- ✓
Anomalies in the /proc filesystem
Why this is correct
Anomalies in the /proc filesystem are a strong rootkit indicator because /proc is a virtual filesystem that reflects kernel data structures, including the live process list and network sockets. Kernel-level rootkits often hook the /proc handler routines or hide their own PIDs and associated entries, so comparing output of ps and netstat against /proc directly can reveal hidden processes or mismatched connection tables. For example, a rootkit may unlink its process from the task list while left visible in /proc's pid directory, or vice versa, and an examiner should inspect /proc/<pid>/cmdline and /proc/net/tcp for subtle inconsistencies.
- ✗
Large number of failed SSH login attempts
Why it's wrong here
A large number of failed SSH login attempts is primarily evidence of an active brute-force attack or credential stuffing campaign, often from botnets, and is commonly visible in auth.log or journald. While an attacker who successfully breaches the system might subsequently install a rootkit, the failed login events themselves do not demonstrate kernel or userland tampering and are not an inherent symptom of a rootkit. This finding should direct the analyst to check for successful logins and post-exploitation artifacts rather than treat it as a rootkit-specific marker.
- ✓
Suspicious loadable kernel modules
Why this is correct
Suspicious loadable kernel modules (LKMs) are a well-documented rootkit vector because they run with kernel privileges and can directly modify system call tables, interrupt handlers, or /proc operations to conceal malicious activity. Legitimate modules appear in lsmod and /proc/modules, but rootkits may hide their module from these listings, so detecting a hidden module requires forensic techniques such as scanning kernel memory or comparing loaded module lists against known-good baselines. Tools like rkhunter and custom kernel integrity checks can flag modules with unusual names or missing files, indicating a possible rootkit injection.
- ✓
Modified system binaries like ls and ps
Why this is correct
Modified system binaries like ls and ps are a classic sign of a userland rootkit, which replaces core utilities with trojanized versions that filter out tell-tale files, processes, and network connections from their output. Instead of operating at the kernel level, this technique simply alters the userspace tools the administrator is likely to run, making it essential to verify binaries with cryptographic hashes against a trusted source or package manager. The presence of suspicious file modification times, changed inode metadata, or mismatched rpm/dpkg checksums can expose such tampering even when the tools appear to function normally.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.