Courseiva
Malware, Social Engineering and Network AttackseasyMultiple ChoiceObjective-mapped

CEH Practice Question: Malware, Social Engineering and Network Attacks

Which of the following is a type of malware that spreads by replicating itself across a network without requiring a host file?

⚠ Common exam trap

A common mix-up: candidates confuse a worm with a virus, as both self-replicate, but the key differentiator is that a worm does not require a host file and spreads via network protocols, while a virus must attach to a host file to propagate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Worm

A worm is a standalone malware that replicates itself across a network by exploiting vulnerabilities or using network protocols (e.g., SMB, RDP, or email) without needing a host file. Unlike viruses, worms do not attach to existing programs; they self-propagate via network connections, often consuming bandwidth and creating backdoors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Worm

    Why this is correct

    A worm is a standalone malware computer program that replicates itself to spread to other computers. Unlike a virus, it does not need to attach to an existing program or host file to propagate. Worms often exploit network vulnerabilities to spread autonomously across networks, consuming bandwidth and system resources, and can carry payloads like backdoors or ransomware. This self-contained, network-aware replication is its defining characteristic.

  • Trojan

    Why it's wrong here

    A Trojan horse is a type of malware that masquerades as legitimate software or a benign file to trick users into executing it. Once activated, it performs malicious actions, such as creating backdoors, stealing data, or installing other malware. Crucially, Trojans do not possess self-replication capabilities; their spread relies entirely on social engineering or other distribution methods, not autonomous propagation.

  • Ransomware

    Why it's wrong here

    Ransomware is a class of malicious software designed to block access to a computer system or encrypt files until a ransom is paid. While some advanced ransomware strains (like WannaCry or NotPetya) have incorporated worm-like self-propagation mechanisms, its primary function is extortion, not replication. Most ransomware relies on other vectors, such as phishing emails or exploited vulnerabilities, for initial infection rather than inherent self-replication.

  • Virus

    Why it's wrong here

    A computer virus is a type of malicious code or program that attaches itself to legitimate programs or documents (host files) and then executes when those programs are run. It requires user interaction or a specific event to activate and spread. Viruses replicate by modifying other computer programs, inserting their own code, and cannot propagate independently without a host program to carry them.

About these practice questions

Courseiva writes every CEH question from scratch — 870 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO types of malware typically require user interaction (e.g., opening a file or clicking a link) to activate? (Select two.)

medium
  • A.Ransomware
  • B.Macro virus
  • C.Polymorphic virus
  • D.Worm
  • E.Trojan horse

Why A: Ransomware often requires user interaction to execute, such as opening a malicious email attachment or clicking a deceptive link, which triggers the encryption process. The Trojan horse similarly relies on user action to install, as it disguises itself as a legitimate file or program that the user willingly opens or runs. Both types depend on social engineering to bypass technical controls and initiate the infection.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.