GCFA Practice Question: Identification of Malicious and Normal Activity
An analyst is examining a Linux server that is suspected of being compromised. The analyst runs 'netstat -anp' and observes a process named 'kworker' with PID 1234 listening on TCP port 4444. The analyst knows that legitimate kworker processes are kernel threads and do not open network sockets. Which of the following conclusions is most appropriate?
⚠ Common exam trap
The trap here is assuming that because the process name matches a legitimate kernel thread, it must be benign, ignoring the fact that kernel threads never listen on network ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The process is likely a malicious backdoor masquerading as a kernel thread, and further analysis should include checking its executable path and parent process.
A process named kworker listening on a network port is anomalous because legitimate kworker threads are kernel threads and do not open sockets. This strongly suggests a malicious process masquerading as a kernel thread. The analyst should investigate the executable path and parent process to confirm and identify the malware.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The process is a legitimate kworker that is part of a user-space threading library, which can create network sockets for inter-process communication.
Why it's wrong here
kworker processes are kernel threads, not user-space threads. User-space threading libraries do not create kernel threads named kworker, and kernel threads do not perform inter-process communication via network sockets. This explanation confuses kernel and user-space concepts and is incorrect for the scenario.
- ✗
The process is a legitimate kworker that has been infected by a rootkit, so the network socket is actually owned by a hidden malicious process.
Why it's wrong here
While rootkits can hide processes, the observation of a kworker with a socket does not imply the kworker itself was infected. Kernel threads cannot be infected in that manner. The more direct explanation is that a malicious process is masquerading as kworker, which is a common technique, rather than a rootkit infecting a kernel thread.
- ✗
The process is a legitimate kernel worker that has been temporarily repurposed by the system for network load balancing.
Why it's wrong here
Legitimate kworker processes are kernel threads that handle workqueues and never listen on network sockets. There is no mechanism by which the kernel repurposes them for network load balancing. This explanation is technically inaccurate and ignores the clear anomaly of a kernel thread with a network socket.
- ✓
The process is likely a malicious backdoor masquerading as a kernel thread, and further analysis should include checking its executable path and parent process.
Why this is correct
Attackers often name malicious processes to mimic legitimate system processes like kworker to avoid detection. A kworker process listening on a port is a strong indicator of a backdoor. The analyst should use tools like 'ls -l /proc/1234/exe' to find the executable and 'ps -fp 1234' to see the parent, which can reveal the malware's origin.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.