CEH Practice Question: Malware, Social Engineering and Network Attacks
During a penetration test, an attacker gains access to a system and wants to maintain persistent remote control. Which type of Trojan is specifically designed for this purpose?
⚠ Common exam trap
The CEH exam often tests the distinction between a backdoor (which provides ongoing remote control) and a downloader (which only fetches other malware), leading candidates to mistakenly choose 'Downloader' because they associate it with remote access, but a downloader does not itself maintain persistence or control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Backdoor
A backdoor Trojan is specifically designed to bypass normal authentication mechanisms and provide an attacker with persistent, unauthorized remote access to a compromised system. Unlike other Trojans that perform a single malicious action, backdoors often install services or modify system startup entries (e.g., registry Run keys, cron jobs) to survive reboots, ensuring long-term control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ransomware
Why it's wrong here
Ransomware's primary function is to encrypt a victim's files or lock access to their system, demanding a ransom payment for decryption or restoration. While it denies the legitimate user access, it does not provide the attacker with direct, interactive remote control or command execution capabilities over the compromised system. Its goal is financial extortion through data unavailability, not persistent operational access.
- ✓
Backdoor
Why this is correct
A backdoor is specifically designed to bypass normal authentication and security mechanisms, providing an attacker with covert and persistent remote access to a compromised system. This unauthorized access allows for full control, including command execution, file manipulation, and further exploitation, directly enabling the attacker to 'gain access' and maintain control over the system.
- ✗
Keylogger
Why it's wrong here
A keylogger is a type of surveillance software whose main purpose is to record and log every keystroke made on a target system, along with other user inputs like clipboard data. While highly effective for stealing credentials and sensitive information, a keylogger does not inherently grant the attacker direct, interactive remote control over the system's operating functions or command-line interface.
- ✗
Downloader
Why it's wrong here
A downloader Trojan's primary role is to retrieve and execute additional malicious payloads from a remote server onto the compromised system. It acts as a delivery mechanism for other malware, but the downloader itself does not offer the attacker direct, interactive remote command and control capabilities over the host system. It facilitates further infection rather than providing direct operational access.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.