Courseiva
Security Concepts →mediumMultiple Select

200-201 Security Concepts Practice Question

Which THREE of the following are common types of malware?

⚠ Common exam trap

Cisco often tests the distinction between security tools (like patches and firewalls) and actual malware types, leading candidates to mistakenly classify protective measures as malicious software.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Virus

Option B (Virus) is correct because a virus is a classic malware category: self-replicating code that attaches to a host file or program and spreads when the host is executed. Option C (Ransomware) is correct because ransomware is a well-known malware type that encrypts or locks victim data and demands payment, often using symmetric keys like AES with an asymmetric-wrapped key. Option D (Worm) is correct because a worm is standalone self-replicating malware that spreads across networks (e.g., via SMB or email) without needing a host file. Option A (Patch) does not belong because a patch is a legitimate software update that fixes vulnerabilities, not malicious code. Option E (Firewall) does not belong because a firewall is a security control that filters network traffic by rules, not a malware type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Patch

    Why it's wrong here

    A patch is a software update that remediates vulnerabilities, the opposite of malicious code; it neither self-replicates nor performs harmful actions. It is tempting because patching is a security task, but the question asks for malware types such as ransomware, spyware, and rootkits.

  • ✓

    Virus

    Why this is correct

    A virus is a self-replicating malware type that attaches to legitimate files or executables, spreading when those hosts run. It satisfies the stem's requirement for a common malware category, distinct from standalone threats such as worms or trojans. Microsoft Entra ID documentation and standard security curricula classify viruses among the core malware families.

  • ✓

    Ransomware

    Why this is correct

    Ransomware is a distinct malware class that encrypts victim data or locks systems, then demands payment for the decryption key. It satisfies the stem's requirement for a common malware type, differing from worms and viruses by its extortion-based payload rather than self-replication.

  • ✓

    Worm

    Why this is correct

    A worm is self-replicating malware that spreads across networks without user interaction or a host file, exploiting vulnerabilities to propagate. It satisfies the stem's requirement for a common malware type, distinguished from viruses by its standalone, autonomous spreading mechanism.

  • ✗

    Firewall

    Why it's wrong here

    A firewall is a network security control that filters traffic, not malicious software; it cannot infect a host, replicate, or execute payloads. It is tempting because firewalls defend against malware, but the question asks for malware categories such as viruses, worms, and trojans.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.