200-201 Security Concepts Practice Question
A security analyst is reviewing a suspicious file found on a user's workstation. The file has a .docx extension but when the analyst inspects its header bytes, the file begins with the magic number for a Windows Portable Executable. The user reports the file arrived as an email attachment. Which type of malware delivery technique does this describe?
⚠ Common exam trap
The trap here is focusing on the .docx extension and assuming a macro virus, when the header bytes reveal the file is actually an executable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A file masquerading as a document but actually an executable
The file's extension claims it is a Word document, but its header bytes match a Windows Portable Executable. This is a classic masquerading technique where malware is disguised as a benign file type to trick users into executing it. The mismatch between the expected file signature and the actual content is the key indicator, distinguishing it from macro viruses, polymorphic code, or rootkits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A file masquerading as a document but actually an executable
Why this is correct
The file uses a .docx extension to appear harmless, but its magic number shows it is a Windows Portable Executable. This masquerading technique tricks users into opening what they believe is a document, potentially executing malicious code. The mismatch between the file extension and its actual header is a strong indicator of disguised malware delivered via email attachment.
- ✗
A rootkit that hides its presence on the system
Why it's wrong here
A rootkit is designed to conceal its presence and maintain privileged access, often by modifying system files or kernel structures. The scenario does not describe concealment mechanisms after execution; it focuses on the file's deceptive appearance before execution. The extension and header mismatch is a delivery trick, not a rootkit's hiding technique.
- ✗
A polymorphic virus that changes its own code to evade detection
Why it's wrong here
Polymorphic malware mutates its code on each infection to avoid signature detection, but it does not necessarily change its file type or masquerade as a document. The scenario describes a static file with an extension mismatch, not code mutation. While the payload could be polymorphic, the described behavior is specifically masquerading, not polymorphism.
- ✗
A macro virus embedded in a legitimate document
Why it's wrong here
A macro virus resides inside a document's macro code and the file remains a valid document format with the expected header. In this case, the file's header indicates it is actually a Windows executable despite the .docx extension, so it is not a document containing malicious macros. The mismatch between extension and file signature points to masquerading rather than macro abuse.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.