220-1102 Security Practice Question
A user receives an email with an attachment named 'Invoice_2024.pdf.exe'. When the user opens the attachment, it downloads and installs additional malicious software on the system without the user's knowledge. Which type of malware is this?
⚠ Common exam trap
Watch out — candidates often confuse a Trojan horse with a worm because both can deliver payloads, but the key distinction is that a Trojan requires user action (opening the attachment) and does not self-replicate, whereas a worm spreads autonomously.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trojan horse
The attachment named 'Invoice_2024.pdf.exe' is a Trojan horse because it disguises itself as a harmless PDF file while actually being an executable (.exe) that, when opened, performs unauthorized actions—in this case, downloading and installing additional malware. Unlike viruses or worms, a Trojan does not self-replicate; it relies on user deception to execute its payload, which matches the scenario where the user unknowingly triggers the malicious activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Worm
Why it's wrong here
A worm is self-replicating malware that spreads over networks without requiring a host file or any user interaction, often exploiting OS or application vulnerabilities. In this scenario, the user must actively open the email attachment, which indicates a social engineering trigger rather than automated propagation. Since the described infection is delivered as a deceptive invoice file and not as a network-transmitted worm, it does not fit this classification.
- ✓
Trojan horse
Why this is correct
The attachment named 'invoice 2024' is a classic Trojan horse: it appears as a legitimate invoice but is actually an executable that, when launched, executes malicious code and can download additional malware. Unlike a worm or virus, a Trojan does not self-replicate; it relies on the user to run it under false pretenses. The deception and user-initiated execution are the defining characteristics of a Trojan horse, making it the correct answer.
- ✗
Rootkit
Why it's wrong here
A rootkit is a stealthy set of tools that hides malicious artifacts and provides persistent privileged (root or kernel-level) access after an initial compromise, often by patching system calls or drivers. The attack chain in this question ends with 'dropping additional malware,' but rootkits are a payload or post-exploitation component, not the initial infection vector itself. The email attachment is the Trojan that would deliver the rootkit, so classifying the attachment itself as a rootkit confuses the container with the eventual impact.
- ✗
Ransomware
Why it's wrong here
Ransomware is a specific payload that encrypts files or locks the system and demands a ransom for decryption, typically announcing the demand with a ransom note or wallpaper. The scenario states that the attachment 'drops additional malware' but does not mention encryption, file locking, or a ransom demand. Without those tell-tale behaviors, the attachment is better characterized as a Trojan downloader rather than ransomware, even though ransomware could be the later payload.
Go deeper
Related to this question
Learn chapter
Malware Classification: Virus, Worm, Ransomware, Rootkit
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Trojan
A Trojan is a type of malware that disguises itself as a legitimate file or program to trick users into installing it, then performs harmful actions without the user's knowledge.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.