200-201 Security Concepts Practice Question
A security analyst is examining a suspicious executable found on a user's workstation. The file appears to be a legitimate PDF document but when opened, it executes code that encrypts the user's files and demands payment. The analyst determines that the file is actually a malicious program disguised as a benign file. Which type of malware is this?
⚠ Common exam trap
The trap here is assuming any malware that encrypts files is automatically ransomware; however, the delivery method (disguised as a benign file) defines it as a Trojan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trojan
The key indicator is the file masquerading as a legitimate PDF while actually being a malicious executable that encrypts files. This deception is the hallmark of a Trojan, which often delivers ransomware payloads. Unlike worms or viruses, Trojans rely on user execution and do not self-replicate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rootkit
Why it's wrong here
A rootkit is designed to hide the presence of other malware and maintain persistent privileged access on a system. The scenario does not mention stealth or hiding; it focuses on a disguised file that encrypts data. Thus, it is not a rootkit.
- ✓
Trojan
Why this is correct
A Trojan is malware that disguises itself as legitimate software or a benign file to trick users into executing it. In this case, the executable appears to be a PDF but actually performs malicious actions like encrypting files. This deception is the defining characteristic of a Trojan, which often delivers ransomware or other payloads.
- ✗
Virus
Why it's wrong here
A virus is malicious code that attaches itself to legitimate files or programs and spreads when those files are executed. While a virus may also disguise itself, the scenario emphasizes the file itself being a standalone disguised executable that directly performs ransomware behavior, which is more characteristic of a Trojan.
- ✗
Worm
Why it's wrong here
A worm is self-replicating malware that spreads across networks without user interaction. The scenario describes a file that requires the user to open it and then encrypts files; it does not mention self-replication or network propagation. Therefore, it is not a worm.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.