Courseiva
Malware, Social Engineering and Network AttacksmediumMultiple ChoiceObjective-mapped

CEH Practice Question: Malware, Social Engineering and Network Attacks

During a penetration test, an attacker gains access to a system and wants to maintain persistent remote control. Which type of Trojan is specifically designed for this purpose?

⚠ Common exam trap

The CEH exam often tests the distinction between a backdoor (which provides ongoing remote control) and a downloader (which only fetches other malware), leading candidates to mistakenly choose 'Downloader' because they associate it with remote access, but a downloader does not itself maintain persistence or control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Backdoor

A backdoor Trojan is specifically designed to bypass normal authentication mechanisms and provide an attacker with persistent, unauthorized remote access to a compromised system. Unlike other Trojans that perform a single malicious action, backdoors often install services or modify system startup entries (e.g., registry Run keys, cron jobs) to survive reboots, ensuring long-term control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Ransomware

    Why it's wrong here

    Ransomware's primary function is to encrypt a victim's files or lock access to their system, demanding a ransom payment for decryption or restoration. While it denies the legitimate user access, it does not provide the attacker with direct, interactive remote control or command execution capabilities over the compromised system. Its goal is financial extortion through data unavailability, not persistent operational access.

  • Backdoor

    Why this is correct

    A backdoor is specifically designed to bypass normal authentication and security mechanisms, providing an attacker with covert and persistent remote access to a compromised system. This unauthorized access allows for full control, including command execution, file manipulation, and further exploitation, directly enabling the attacker to 'gain access' and maintain control over the system.

  • Keylogger

    Why it's wrong here

    A keylogger is a type of surveillance software whose main purpose is to record and log every keystroke made on a target system, along with other user inputs like clipboard data. While highly effective for stealing credentials and sensitive information, a keylogger does not inherently grant the attacker direct, interactive remote control over the system's operating functions or command-line interface.

  • Downloader

    Why it's wrong here

    A downloader Trojan's primary role is to retrieve and execute additional malicious payloads from a remote server onto the compromised system. It acts as a delivery mechanism for other malware, but the downloader itself does not offer the attacker direct, interactive remote command and control capabilities over the host system. It facilitates further infection rather than providing direct operational access.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.