200-201 Security Concepts Practice Question
A security analyst is reviewing a suspicious file recovered from a compromised endpoint. The file contains a macro that, when opened, launches PowerShell to download a second-stage payload from a remote server. The analyst wants to classify this file based on its behavior. Which classification is most accurate?
⚠ Common exam trap
The trap here is labeling the threat fileless merely because PowerShell is involved, even though a macro document on disk is a clear file-based dropper.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A dropper that delivers a malicious payload onto the system
The macro document functions as a dropper: its sole purpose is to execute and pull a second-stage payload onto the host. Droppers are common initial-access vehicles, and classifying by function helps the analyst understand the infection chain and prioritize response. The delivered payload may later exhibit other behaviors, but the file in hand is a dropper.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A dropper that delivers a malicious payload onto the system
Why this is correct
A dropper is code whose purpose is to install or download malware onto a target. The macro document fits this role: it executes on open and fetches a second-stage payload, establishing the infection. Classifying it as a dropper correctly describes its function in the attack chain rather than the payload it delivers.
- ✗
A rootkit because it hides the PowerShell process
Why it's wrong here
A rootkit modifies the operating system to conceal malicious processes, files, or registry keys from the user and defenders. The scenario describes only a macro that launches PowerShell to download a payload, with no evidence of system-level concealment, so rootkit classification is unsupported by the observed behavior.
- ✗
Fileless malware because it uses a scripting engine
Why it's wrong here
Fileless malware resides in memory and avoids writing artifacts to disk. Here a document file with an embedded macro exists on disk and is the initial infection vector, so the presence of a scripting engine in the second stage does not make the entire threat fileless; the macro document is a tangible file artifact.
- ✗
A logic bomb because it triggers on a specific event
Why it's wrong here
A logic bomb executes its malicious action only when a defined condition is met, such as a date or the removal of an employee account. The macro here runs immediately when the document is opened and downloads a payload, which is dropper behavior rather than a dormant, condition-triggered payload.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.