200-201 Security Concepts Practice Question
Which type of malware is designed to replicate itself and spread to other systems without user intervention?
⚠ Common exam trap
200-201 often tests the distinction between viruses and worms — candidates must remember that worms self-replicate without user intervention, while viruses require a host and user action to spread.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Worm
A worm is malware that self-replicates and spreads to other systems automatically, without requiring user interaction or a host program. It typically exploits network vulnerabilities or weak credentials to propagate across networks. This autonomous spreading behavior is the defining characteristic that distinguishes worms from other malware types.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Virus
Why it's wrong here
A virus requires a host file and user action, such as executing an infected program, to propagate; it cannot self-replicate across systems unaided. It is tempting because viruses do spread between machines, but that transmission depends on human behaviour. A virus would be the correct answer if the stem described malware activated by opening an attachment.
- ✗
Ransomware
Why it's wrong here
Ransomware encrypts files and demands payment; it does not self-replicate or spread autonomously to other hosts. It is tempting because ransomware spreads rapidly across networks, but it relies on user action or exploited vulnerabilities, so it would be correct when the scenario describes extortion rather than self-propagation.
- ✗
Trojan
Why it's wrong here
A Trojan disguises itself as legitimate software and depends on a user executing it, so it cannot self-replicate or spread unaided — failing the "without user intervention" requirement. It is tempting because Trojans do deliver payloads and enable remote access, making them the right choice when the scenario describes deception rather than autonomous propagation.
- ✓
Worm
Why this is correct
A worm self-replicates and propagates across networks autonomously, exploiting vulnerabilities or weak credentials without requiring a user to open a file or click a link. This matches the stem's constraint of spreading without user intervention, unlike viruses, which need host execution.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.