A systems administrator receives the following alert from a file integrity monitoring tool: The hash of the cmd.exe file has changed. The systems administrator checks the OS logs and notices that no patches were applied in the last two months. Which of the following most likely occurred?
Choose an answer
Tap an option to check your answer.
Correct answer: A rootkit was deployed..
Why this is the answer
The most likely explanation for an unexpected change in the hash of a critical system file like cmd.exe, especially when no patches have been applied, is a rootkit. Rootkits are stealthy malware designed to gain privileged access to a computer while actively hiding their presence. They often modify system files or core operating system components to maintain persistence and evade detection. Changing file permissions by an end user would not alter the file's hash, only its access rights. A cryptographic collision is theoretically possible but extremely rare in practice for widely used hashing algorithms and is highly unlikely to be the cause of a single file's hash change in this scenario. A snapshot of the file system would capture the current state but wouldn't inherently change the hash of an existing file on the live system.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed