Courseiva
easyMultiple Select

FC0-U71 Practice Question: Which TWO of the following are types of malware?

Which TWO of the following are types of malware?

⚠ Common exam trap

Watch out — candidates often confuse security tools (patches, encryption, firewalls) with malware types, or mistakenly think encryption itself is malicious, whereas encryption is a neutral technique used by both security software and some malware (e.g., ransomware) to lock data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Virus

A virus (C) is a type of malware: it is a self-replicating program that attaches itself to a host file or boot sector and spreads when the infected file is executed, often requiring user action. A worm (D) is also malware: it is a standalone, self-replicating program that spreads across networks by exploiting vulnerabilities or using file-sharing/email mechanisms without needing a host file or user interaction. The other options are not malware: a patch (A) is a legitimate software update that fixes bugs or closes vulnerabilities, encryption (B) is a security technique that encodes data to protect confidentiality, and a firewall (E) is a network security device or software that filters traffic based on rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Patch

    Why it's wrong here

    A patch is a software update that fixes vulnerabilities or bugs, not malicious code, so it cannot be a malware type. It is tempting because patches relate to security, and applying them is a remediation step after malware incidents, but they are defensive updates rather than threats themselves.

  • ✗

    Encryption

    Why it's wrong here

    Encryption is a protective technique that renders data unreadable without a key, not a category of malicious software. It is tempting because ransomware encrypts victim files, but encryption itself is a legitimate security control; the malware is the ransomware, not the encryption mechanism.

  • ✓

    Virus

    Why this is correct

    A virus is malicious code that attaches to a host file or program and replicates when the user executes it, requiring human action to spread. This satisfies the malware classification, distinguishing it from standalone self-propagating threats.

  • ✓

    Worm

    Why this is correct

    A worm is self-replicating malware that spreads across networks autonomously, exploiting vulnerabilities without user interaction or a host file. This satisfies the malware classification, distinguishing it from viruses that require a user to execute an infected file.

  • ✗

    Firewall

    Why it's wrong here

    A firewall is a network security control that filters traffic by rules, not malicious software. It is tempting because firewalls defend against malware and appear in the same security discussions, but they are preventive infrastructure; malware types describe the malicious code itself, such as viruses or worms.

About these practice questions

One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.