CEH Practice Question: Malware, Social Engineering and Network Attacks
Which malware type is characterized by self-replication across networks without needing a host file?
⚠ Common exam trap
EC-CEH often tests the distinction between a worm and a virus, where the trap is that candidates confuse self-replication across networks (worm) with self-replication within a single system via host files (virus).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Worm
A worm is a standalone malware program that replicates itself across network connections without requiring a host file or user intervention. It exploits vulnerabilities in network protocols or services (e.g., SMB, RDP) to propagate autonomously, as seen with WannaCry's use of EternalBlue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Worm
Why this is correct
Worms are a distinct category of malware known for their ability to self-replicate and propagate independently across computer networks without requiring user interaction. They exploit vulnerabilities in network protocols or services to spread from one system to another, consuming bandwidth and system resources. This autonomous replication is their defining characteristic, enabling rapid and widespread infection.
- ✗
Trojan
Why it's wrong here
A Trojan horse is a type of malicious software that disguises itself as legitimate software to trick users into executing it. Unlike worms, Trojans do not possess self-replication capabilities and rely entirely on social engineering or other deceptive tactics to gain initial access. Once executed, they can perform various malicious actions, but their spread is not autonomous.
- ✗
Rootkit
Why it's wrong here
Rootkits are designed to conceal the presence of other malicious software or activities on a system, often by modifying operating system components or kernel functions. Their primary function is stealth and persistence, allowing attackers to maintain covert access without detection. However, rootkits lack any inherent self-replication mechanism and must be installed through other means, such as a Trojan or exploit.
- ✗
Ransomware
Why it's wrong here
Ransomware is a type of malware that encrypts a victim's files or locks their computer system, demanding a ransom payment, typically in cryptocurrency, for decryption or restoration of access. While some modern ransomware variants may incorporate worm-like propagation capabilities (e.g., WannaCry), self-replication is not an intrinsic defining characteristic of ransomware itself. Its core function is data denial and extortion, not autonomous network spread.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.