200-201 Security Concepts Practice Question
A security team is analyzing a malware infection. Which two characteristics are typical of a worm? (Choose two.)
⚠ Common exam trap
The trap is confusing worm traits with virus or Trojan traits — candidates must remember that 'no user interaction' and 'self-replication across networks' are the two defining worm characteristics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exploits vulnerabilities to spread without user interaction
Option A is correct because a worm actively exploits vulnerabilities (for example, unpatched SMB or RDP flaws) to propagate autonomously across systems without requiring any user action such as clicking a link or opening an attachment. Option E is correct because self-replication is the defining trait of a worm: it copies itself from host to host over network connections, often scanning for new targets and consuming bandwidth. Option B is wrong because requiring a host file to propagate describes a virus, which needs to infect an executable or document, not a worm. Option C is wrong because disguising itself as a legitimate program is characteristic of a Trojan, which relies on deception rather than self-replication. Option D is wrong because attaching to an email to spread is typical of a mass-mailing virus or email-based malware, not the network-propagating worm behavior described here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Exploits vulnerabilities to spread without user interaction
Why this is correct
Exploiting vulnerabilities lets the worm propagate autonomously across networks, satisfying the stem's requirement for self-replication without user interaction. Unlike viruses, which need a host file or user action to execute, worms spread directly between systems, making this a defining characteristic of worm behaviour during malware analysis.
- ✗
Requires a host file to propagate
Why it's wrong here
Worms self-replicate and spread across networks without attaching to a host file, so requiring one contradicts their defining trait. It is tempting because fileless versus file-based classification matters for viruses, which do need a host; that distinction would be the correct answer if the question asked about viruses rather than worms.
- ✗
Disguises itself as a legitimate program
Why it's wrong here
Disguising itself as a legitimate program describes a Trojan, which relies on user execution rather than self-replication. A worm propagates autonomously across networks by exploiting vulnerabilities, without a host file or user action. Trojans are the right answer when the scenario involves deceptive executables tricking users into launching malicious payloads.
- ✗
Attaches to an email to spread
Why it's wrong here
Email attachment is a vector used by viruses and mass-mailing malware, not a defining worm trait; worms propagate autonomously over network services. It is tempting because many real-world worms have spread via email, but that describes delivery method, not the self-replicating mechanism the question asks about.
- ✓
Self-replicates across networks
Why this is correct
Worms self-replicate, copying themselves to other hosts across networks without a carrier file or human trigger. This autonomous replication satisfies the stem's worm characteristic, contrasting with viruses that need a host file and user action.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.