Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user receives an email with an attachment named 'Invoice_2024.pdf.exe'. When the user opens the attachment, it downloads and installs additional malicious software on the system without the user's knowledge. Which type of malware is this?

⚠ Common exam trap

Watch out — candidates often confuse a Trojan horse with a worm because both can deliver payloads, but the key distinction is that a Trojan requires user action (opening the attachment) and does not self-replicate, whereas a worm spreads autonomously.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Trojan horse

The attachment named 'Invoice_2024.pdf.exe' is a Trojan horse because it disguises itself as a harmless PDF file while actually being an executable (.exe) that, when opened, performs unauthorized actions—in this case, downloading and installing additional malware. Unlike viruses or worms, a Trojan does not self-replicate; it relies on user deception to execute its payload, which matches the scenario where the user unknowingly triggers the malicious activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Worm

    Why it's wrong here

    A worm is self-replicating malware that spreads over networks without requiring a host file or any user interaction, often exploiting OS or application vulnerabilities. In this scenario, the user must actively open the email attachment, which indicates a social engineering trigger rather than automated propagation. Since the described infection is delivered as a deceptive invoice file and not as a network-transmitted worm, it does not fit this classification.

  • ✓

    Trojan horse

    Why this is correct

    The attachment named 'invoice 2024' is a classic Trojan horse: it appears as a legitimate invoice but is actually an executable that, when launched, executes malicious code and can download additional malware. Unlike a worm or virus, a Trojan does not self-replicate; it relies on the user to run it under false pretenses. The deception and user-initiated execution are the defining characteristics of a Trojan horse, making it the correct answer.

  • ✗

    Rootkit

    Why it's wrong here

    A rootkit is a stealthy set of tools that hides malicious artifacts and provides persistent privileged (root or kernel-level) access after an initial compromise, often by patching system calls or drivers. The attack chain in this question ends with 'dropping additional malware,' but rootkits are a payload or post-exploitation component, not the initial infection vector itself. The email attachment is the Trojan that would deliver the rootkit, so classifying the attachment itself as a rootkit confuses the container with the eventual impact.

  • ✗

    Ransomware

    Why it's wrong here

    Ransomware is a specific payload that encrypts files or locks the system and demands a ransom for decryption, typically announcing the demand with a ransom note or wallpaper. The scenario states that the attachment 'drops additional malware' but does not mention encryption, file locking, or a ransom demand. Without those tell-tale behaviors, the attachment is better characterized as a Trojan downloader rather than ransomware, even though ransomware could be the later payload.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.