220-1102 Security Practice Question
A user receives an email that appears to be from a known vendor, requesting payment for an invoice. The email includes a Microsoft Word document attachment. When the user opens the document, a macro runs and installs a backdoor on the system. Which type of malware is this?
⚠ Common exam trap
Candidates often confuse a trojan horse with a virus or worm because all involve malicious code, but the defining characteristic of a trojan is its deceptive appearance as a legitimate file, not self-replication or file infection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trojan
The malware described is a trojan horse. A trojan horse disguises itself as a legitimate file (in this case, a Microsoft Word document from a known vendor) to trick the user into opening it. Once opened, the embedded macro executes, installing a backdoor—a classic trojan behavior where the malicious payload is hidden inside seemingly benign software.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Virus
Why it's wrong here
A virus is a self-replicating program that inserts its code into other executable files or boot sectors to spread from host to host. In this scenario, the user must open an attachment and manually enable a macro, but the macro does not modify or infect other files; it directly drops a backdoor. Because there is no host file infection or self-replication step, classifying this as a virus is inaccurate—viruses require a propagation mechanism that simply is not present here.
- ✓
Trojan
Why this is correct
This is a classic Trojan horse: it arrives disguised as a legitimate, trusted communication from a known vendor, exploiting the user's confidence to convince them to open the attachment. Once the user enables the macro, the malicious code executes and installs a backdoor—exactly the kind of hidden, unauthorized remote access that Trojans commonly deliver. The defining trait is the deception and the mismatched payload, not self-replication or file infection.
- ✗
Worm
Why it's wrong here
A worm is a standalone malware type that self-replicates and autonomously spreads across networks, often by exploiting vulnerabilities or using system services without requiring user interaction. In this incident, the attack relies on the victim opening an email attachment and enabling a macro—actions that involve social engineering and manual execution. Because the malware does not actively propagate itself to other systems, it fails the core criterion of a worm, making that classification wrong.
- ✗
Ransomware
Why it's wrong here
Ransomware is a type of malware whose primary goal is financial extortion via file encryption; it locks the victim's data and demands payment for the decryption key. The activity described here, however, is the silent installation of a backdoor, which enables persistent covert access and remote control, not data encryption or a ransom demand. While both can be financially motivated, the absence of any encryption or extortion step makes ransomware an incorrect label for this behavior.
Go deeper
Related to this question
Learn chapter
Malware Classification: Virus, Worm, Ransomware, Rootkit
Key term
Trojan
A Trojan is a type of malware that disguises itself as a legitimate file or program to trick users into installing it, then performs harmful actions without the user's knowledge.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A user receives an email that appears to be from a well-known shipping company, asking them to download an invoice attachment. The attachment contains a macro-enabled Word document. What type of malware is most likely being delivered?
easy- A.Ransomware
- B.Worm
- ✓ C.Trojan
- D.Rootkit
Why C: The email attachment is a macro-enabled Word document, which is a classic delivery mechanism for a Trojan. A Trojan disguises itself as legitimate software (here, an invoice) to trick the user into enabling macros, which then execute malicious code to install malware or steal data. This matches the social engineering and macro-based attack vector described.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.