easyMultiple Select
FC0-U71 Practice Question: Which TWO of the following are types of malware?
Which TWO of the following are types of malware?
⚠ Common exam trap
Watch out — candidates often confuse security tools (patches, encryption, firewalls) with malware types, or mistakenly think encryption itself is malicious, whereas encryption is a neutral technique used by both security software and some malware (e.g., ransomware) to lock data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Virus
A virus (C) is a type of malware: it is a self-replicating program that attaches itself to a host file or boot sector and spreads when the infected file is executed, often requiring user action. A worm (D) is also malware: it is a standalone, self-replicating program that spreads across networks by exploiting vulnerabilities or using file-sharing/email mechanisms without needing a host file or user interaction. The other options are not malware: a patch (A) is a legitimate software update that fixes bugs or closes vulnerabilities, encryption (B) is a security technique that encodes data to protect confidentiality, and a firewall (E) is a network security device or software that filters traffic based on rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patch
Why it's wrong here
A patch is a software update that fixes vulnerabilities or bugs, not malicious code, so it cannot be a malware type. It is tempting because patches relate to security, and applying them is a remediation step after malware incidents, but they are defensive updates rather than threats themselves.
- ✗
Encryption
Why it's wrong here
Encryption is a protective technique that renders data unreadable without a key, not a category of malicious software. It is tempting because ransomware encrypts victim files, but encryption itself is a legitimate security control; the malware is the ransomware, not the encryption mechanism.
- ✓
Virus
Why this is correct
A virus is malicious code that attaches to a host file or program and replicates when the user executes it, requiring human action to spread. This satisfies the malware classification, distinguishing it from standalone self-propagating threats.
- ✓
Worm
Why this is correct
A worm is self-replicating malware that spreads across networks autonomously, exploiting vulnerabilities without user interaction or a host file. This satisfies the malware classification, distinguishing it from viruses that require a user to execute an infected file.
- ✗
Firewall
Why it's wrong here
A firewall is a network security control that filters traffic by rules, not malicious software. It is tempting because firewalls defend against malware and appear in the same security discussions, but they are preventive infrastructure; malware types describe the malicious code itself, such as viruses or worms.
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.