Courseiva
Security Concepts →mediumMultiple Select

200-201 Security Concepts Practice Question

A security team is analyzing a malware infection. Which two characteristics are typical of a worm? (Choose two.)

⚠ Common exam trap

The trap is confusing worm traits with virus or Trojan traits — candidates must remember that 'no user interaction' and 'self-replication across networks' are the two defining worm characteristics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exploits vulnerabilities to spread without user interaction

Option A is correct because a worm actively exploits vulnerabilities (for example, unpatched SMB or RDP flaws) to propagate autonomously across systems without requiring any user action such as clicking a link or opening an attachment. Option E is correct because self-replication is the defining trait of a worm: it copies itself from host to host over network connections, often scanning for new targets and consuming bandwidth. Option B is wrong because requiring a host file to propagate describes a virus, which needs to infect an executable or document, not a worm. Option C is wrong because disguising itself as a legitimate program is characteristic of a Trojan, which relies on deception rather than self-replication. Option D is wrong because attaching to an email to spread is typical of a mass-mailing virus or email-based malware, not the network-propagating worm behavior described here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Exploits vulnerabilities to spread without user interaction

    Why this is correct

    Exploiting vulnerabilities lets the worm propagate autonomously across networks, satisfying the stem's requirement for self-replication without user interaction. Unlike viruses, which need a host file or user action to execute, worms spread directly between systems, making this a defining characteristic of worm behaviour during malware analysis.

  • ✗

    Requires a host file to propagate

    Why it's wrong here

    Worms self-replicate and spread across networks without attaching to a host file, so requiring one contradicts their defining trait. It is tempting because fileless versus file-based classification matters for viruses, which do need a host; that distinction would be the correct answer if the question asked about viruses rather than worms.

  • ✗

    Disguises itself as a legitimate program

    Why it's wrong here

    Disguising itself as a legitimate program describes a Trojan, which relies on user execution rather than self-replication. A worm propagates autonomously across networks by exploiting vulnerabilities, without a host file or user action. Trojans are the right answer when the scenario involves deceptive executables tricking users into launching malicious payloads.

  • ✗

    Attaches to an email to spread

    Why it's wrong here

    Email attachment is a vector used by viruses and mass-mailing malware, not a defining worm trait; worms propagate autonomously over network services. It is tempting because many real-world worms have spread via email, but that describes delivery method, not the self-replicating mechanism the question asks about.

  • ✓

    Self-replicates across networks

    Why this is correct

    Worms self-replicate, copying themselves to other hosts across networks without a carrier file or human trigger. This autonomous replication satisfies the stem's worm characteristic, contrasting with viruses that need a host file and user action.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.