Courseiva
Security Concepts →easyMultiple Select

200-201 Security Concepts Practice Question

Which TWO of the following are examples of malware that rely on user interaction to spread? (Select two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Trojan

Option C (Trojan) is correct because a Trojan horse is malware disguised as legitimate software, and it requires the user to download and execute the file before it can infect the system — the user's action is the trigger for the infection. Option D (Virus) is correct because a virus must attach itself to a host file or program and typically needs the user to run that infected file or share it (e.g., via email attachment or USB drive) for it to propagate. By contrast, Option B (Worm) is incorrect because worms self-replicate and spread across networks automatically without any user interaction. Option A (Rootkit) is incorrect because it is a stealth tool for maintaining privileged access, not a self-spreading mechanism, and Option E (Ransomware) is incorrect because it is defined by its payload (encrypting data for extortion) rather than by a user-interaction-dependent spreading method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rootkit

    Why it's wrong here

    A rootkit hides itself within the operating system to maintain privileged persistence, so it does not propagate by prompting a user to click or open anything. It is tempting because rootkits are genuinely malicious and stealthy, but they are installed after another vector delivers them, typically by an attacker with existing access.

  • ✗

    Worm

    Why it's wrong here

    A worm self-propagates across networks by exploiting vulnerabilities, so it needs no user action to spread — the opposite of the stem's requirement. It is tempting because worms do spread malware, and it would be correct if the question asked about propagation without interaction, such as Sasser or Conficker.

  • ✓

    Trojan

    Why this is correct

    A Trojan disguises itself as legitimate software, so the victim must execute or install it before it runs. That dependency on the user launching the file satisfies the stem's user-interaction requirement, unlike worms, which self-propagate across networks without any user action.

  • ✓

    Virus

    Why this is correct

    A virus attaches to a host file and only replicates when the user runs or opens that infected file. This dependency on user execution satisfies the stem's user-interaction requirement, distinguishing it from worms, which spread autonomously across networks without any user action.

  • ✗

    Ransomware

    Why it's wrong here

    Ransomware can spread via drive-by downloads or worms, not necessarily user interaction.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.