hardMultiple ChoiceObjective-mapped
220-1102 Practice Question: That their computer is sending out a large amount…
A user reports that their computer is sending out a large amount of network traffic even when they are not using the internet. The antivirus detects a file named 'expl0rer.exe' in the startup folder. What type of malware is most likely causing this behavior?
⚠ Common exam trap
Many candidates confuse 'botnet' with 'trojan' because both can be installed stealthily, but the question's emphasis on sustained network activity is the key differentiator for botnet behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Botnet
The file name 'expl0rer.exe' mimics the legitimate 'explorer.exe' but uses a zero in place of the 'o', a common obfuscation technique. The symptom of high outbound network traffic without user activity, combined with the file's presence in the startup folder, strongly indicates the computer is part of a botnet. Botnet malware connects to a command-and-control (C2) server to receive instructions, often used for DDoS attacks or spam relays, which generates constant network activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spyware
Why it's wrong here
Spyware primarily focuses on covert data collection, such as keystrokes, browsing history, or personal information. While it does transmit this collected data back to an attacker, the volume is generally low unless it's specifically exfiltrating large, pre-identified files. Therefore, it is unlikely to be the primary cause of consistently high outbound network traffic, as its core function isn't about massive, sustained data transfer from the user's machine.
- ✓
Botnet
Why this is correct
A botnet infection turns a user's computer into a "bot" or "zombie" machine, remotely controlled by an attacker. These bots are then used to participate in coordinated malicious activities, such as Distributed Denial of Service (DDoS) attacks, sending spam emails, or cryptocurrency mining. These activities inherently generate significant and sustained outbound network traffic as the compromised machine actively engages in these operations, making it the most fitting answer for a computer 'sending out' a lot of data.
- ✗
Virus
Why it's wrong here
A computer virus is a type of malware that attaches itself to legitimate programs or documents and replicates by infecting other files on the same system or network shares. While some viruses might have payloads that cause network activity, their primary function of replication itself does not inherently or consistently generate high volumes of outbound network traffic. The 'sending out' aspect described in the question is not a defining characteristic of a typical virus's core operational mechanism.
- ✗
Trojan
Why it's wrong here
A Trojan horse is a malicious program disguised as legitimate software that, once executed, performs harmful actions, often by creating backdoors for remote access or dropping other malware. While Trojans may initiate network connections for command and control (C2) or to download additional payloads, their primary function isn't to generate sustained, high outbound network traffic from the infected machine. Any network activity would typically be for communication rather than continuous, high-volume data transmission.
Go deeper
Related to this question
Learn chapter
Windows Command Line Tools
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Denial-of-service
A Denial-of-service (DoS) attack is an attempt to make a computer, network, or online service unavailable to its intended users by overwhelming it with fake traffic or requests.
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.