An analyst is investigating a malware infection on a workstation. The malware appears to be a trojan that downloads additional payloads and allows remote control. The analyst needs to classify the malware based on its behavior. Which THREE characteristics match this description? (Choose three.)
Remote-access trojans install a backdoor that grants the attacker interactive control of the workstation, satisfying the stem's "allows remote control" constraint. This unauthorised access is the defining behavioural characteristic distinguishing a RAT from payloads that merely download or self-replicate, so it matches the classification requirement directly.
Why this answer
The scenario describes a trojan that downloads additional payloads and allows remote control, so the correct characteristics are A, B, and C. Option A is correct because allowing remote control is precisely unauthorized remote access, the defining behavior of a Remote Access Trojan (RAT). Option B is correct because downloading additional payloads is a dropper/downloader behavior, where the initial malware retrieves and installs further malicious software.
Option C is correct because a trojan typically relies on social engineering or user execution (e.g., opening an attachment or running a file) to activate, unlike worms or exploits that can execute without interaction. Option D is incorrect because self-replication without user interaction describes a worm, not a trojan. Option E is incorrect because encrypting files and demanding ransom describes ransomware, which is not stated in this scenario.
Exam trap
Cisco often tests the distinction between trojans and worms by emphasizing that trojans require user interaction to execute, whereas worms self-replicate and spread automatically without user action.