220-1102 Security Practice Question
A user receives an email that appears to be from a well-known shipping company, asking them to download an invoice attachment. The attachment contains a macro-enabled Word document. What type of malware is most likely being delivered?
⚠ Common exam trap
Test-takers frequently confuse the delivery method (macro-enabled document) with the malware type, assuming any malicious attachment is ransomware, when the key is that a Trojan is specifically disguised as a legitimate file to trick the user.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trojan
The email attachment is a macro-enabled Word document, which is a classic delivery mechanism for a Trojan. A Trojan disguises itself as legitimate software (here, an invoice) to trick the user into enabling macros, which then execute malicious code to install malware or steal data. This matches the social engineering and macro-based attack vector described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ransomware
Why it's wrong here
While ransomware can be delivered via macro, the question asks for the type of malware being delivered. The attachment itself is a Trojan that may later download ransomware, but the initial delivery is typically a Trojan.
- ✗
Worm
Why it's wrong here
A worm is standalone malware that self-replicates and spreads automatically across networks, often by exploiting OS or application vulnerabilities without any user intervention. In contrast, a macro-enabled document attachment requires the recipient to open the file and explicitly enable macros (or fall for a social-engineering prompt) before any code runs. Since the attack depends on this user action and the attachment does not propagate itself to other systems, it is not a worm. Even if the macro later drops a worm component, the initial delivered payload is a Trojan.
- ✓
Trojan
Why this is correct
A Trojan is a type of malware that disguises itself as a legitimate, desirable file—in this case, an innocuous-looking document with embedded macros. The attacker uses social engineering to convince the user to open the attachment and enable macros, at which point the macro code executes and installs the Trojan payload. Trojans are often used as a delivery mechanism; the payload may subsequently download additional malware such as ransomware or banking stealers. This matches the scenario perfectly: the email appears legitimate, the attachment is the disguised vector, and the malware is delivered only after the user interacts with it.
- ✗
Rootkit
Why it's wrong here
A rootkit is a collection of malicious tools designed to give an attacker persistent, privileged access to a system while actively hiding its presence—for example, by intercepting system calls, manipulating APIs, or patching the kernel to conceal processes and files. Rootkits are typically installed after an initial compromise and require deep system-level access to install, making them an unlikely payload for a simple macro-enabled email attachment. While a macro could theoretically download and install a rootkit later, the initial delivered malware itself is not a rootkit because it does not immediately demonstrate stealth or persistence mechanisms. Rootkit delivery usually involves a separate exploit or a multi-stage attack, not a single macro document.
Go deeper
Related to this question
Learn chapter
Malware Types and Removal
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.