Courseiva
Security Concepts →hardMultiple Choice

200-201 Security Concepts Practice Question

A security analyst is reviewing a suspicious file recovered from a compromised endpoint. The file contains a macro that, when opened, launches PowerShell to download a second-stage payload from a remote server. The analyst wants to classify this file based on its behavior. Which classification is most accurate?

⚠ Common exam trap

The trap here is labeling the threat fileless merely because PowerShell is involved, even though a macro document on disk is a clear file-based dropper.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A dropper that delivers a malicious payload onto the system

The macro document functions as a dropper: its sole purpose is to execute and pull a second-stage payload onto the host. Droppers are common initial-access vehicles, and classifying by function helps the analyst understand the infection chain and prioritize response. The delivered payload may later exhibit other behaviors, but the file in hand is a dropper.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A dropper that delivers a malicious payload onto the system

    Why this is correct

    A dropper is code whose purpose is to install or download malware onto a target. The macro document fits this role: it executes on open and fetches a second-stage payload, establishing the infection. Classifying it as a dropper correctly describes its function in the attack chain rather than the payload it delivers.

  • ✗

    A rootkit because it hides the PowerShell process

    Why it's wrong here

    A rootkit modifies the operating system to conceal malicious processes, files, or registry keys from the user and defenders. The scenario describes only a macro that launches PowerShell to download a payload, with no evidence of system-level concealment, so rootkit classification is unsupported by the observed behavior.

  • ✗

    Fileless malware because it uses a scripting engine

    Why it's wrong here

    Fileless malware resides in memory and avoids writing artifacts to disk. Here a document file with an embedded macro exists on disk and is the initial infection vector, so the presence of a scripting engine in the second stage does not make the entire threat fileless; the macro document is a tangible file artifact.

  • ✗

    A logic bomb because it triggers on a specific event

    Why it's wrong here

    A logic bomb executes its malicious action only when a defined condition is met, such as a date or the removal of an employee account. The macro here runs immediately when the document is opened and downloads a payload, which is dropper behavior rather than a dormant, condition-triggered payload.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.