Courseiva
Security Concepts →hardMultiple Select

200-201 Security Concepts Practice Question

An analyst is investigating a malware infection on a workstation. The malware appears to be a trojan that downloads additional payloads and allows remote control. The analyst needs to classify the malware based on its behavior. Which THREE characteristics match this description? (Choose three.)

⚠ Common exam trap

Cisco often tests the distinction between trojans and worms by emphasizing that trojans require user interaction to execute, whereas worms self-replicate and spread automatically without user action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It provides unauthorized remote access to the system.

The scenario describes a trojan that downloads additional payloads and allows remote control, so the correct characteristics are A, B, and C. Option A is correct because allowing remote control is precisely unauthorized remote access, the defining behavior of a Remote Access Trojan (RAT). Option B is correct because downloading additional payloads is a dropper/downloader behavior, where the initial malware retrieves and installs further malicious software. Option C is correct because a trojan typically relies on social engineering or user execution (e.g., opening an attachment or running a file) to activate, unlike worms or exploits that can execute without interaction. Option D is incorrect because self-replication without user interaction describes a worm, not a trojan. Option E is incorrect because encrypting files and demanding ransom describes ransomware, which is not stated in this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It provides unauthorized remote access to the system.

    Why this is correct

    Remote-access trojans install a backdoor that grants the attacker interactive control of the workstation, satisfying the stem's "allows remote control" constraint. This unauthorised access is the defining behavioural characteristic distinguishing a RAT from payloads that merely download or self-replicate, so it matches the classification requirement directly.

  • ✓

    It downloads and installs additional malicious software.

    Why this is correct

    Downloading and installing additional malicious software is the defining behaviour of a trojan downloader, directly matching the stem's requirement to classify malware that fetches further payloads. This characteristic satisfies the "downloads additional payloads" constraint, distinguishing it from viruses that self-replicate or worms that spread autonomously across networks.

  • ✓

    It requires user interaction to execute.

    Why this is correct

    Trojans rely on social engineering, so the victim must launch the disguised file themselves before the downloader and remote-control payloads activate. This user-initiated execution is the defining behavioural trait distinguishing a trojan from worms or exploits that spread or run without any interaction.

  • ✗

    It self-replicates without user interaction.

    Why it's wrong here

    Self-replication without user interaction defines worms, not trojans; a trojan relies on user execution and does not propagate itself. It is tempting because rapid spread is commonly associated with malware outbreaks, and it would be correct if the sample propagated autonomously across hosts via network exploits.

  • ✗

    It encrypts files and demands ransom.

    Why it's wrong here

    Ransomware encryption is a distinct behaviour; the stem describes a trojan with downloader and remote-access capability, with no file encryption or extortion. It is tempting because ransomware is high-profile malware, and it would be correct if the analyst observed mass file encryption plus a ransom note.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.