Courseiva
Malware, Social Engineering and Network AttackseasyMultiple ChoiceObjective-mapped

CEH Practice Question: Malware, Social Engineering and Network Attacks

Which of the following malware types is characterized by self-replication without requiring a host file or program, and spreading across networks automatically?

⚠ Common exam trap

Candidates often confuse a worm with a virus, assuming both require a host file, but worms are standalone and self-propagating via network vulnerabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Worm

A worm is a standalone malware type that self-replicates and spreads across networks automatically without needing a host file or program. It exploits network vulnerabilities or uses social engineering to propagate, often consuming bandwidth and system resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Worm

    Why this is correct

    Worms are a class of standalone malware that self-replicate and propagate across computer networks without requiring a host program or user intervention. They exploit network vulnerabilities or misconfigurations to spread automatically from one system to another, consuming bandwidth and system resources. This autonomous propagation is their defining characteristic, enabling rapid infection across interconnected devices.

  • Trojan horse

    Why it's wrong here

    A Trojan horse is a type of malware that masquerades as legitimate software, tricking users into executing it. Unlike worms or viruses, Trojans do not self-replicate; their propagation relies entirely on social engineering and user action to install the deceptive program. Once executed, they can perform various malicious activities, such as creating backdoors, stealing data, or installing other malware, but they lack inherent spreading mechanisms.

  • Virus

    Why it's wrong here

    A computer virus is a malicious program that attaches itself to a legitimate program or document, requiring a host file to exist. It relies on user interaction, such as opening an infected file or executing a program, to activate and spread. Viruses propagate by inserting copies of themselves into other executable code or documents, often causing damage or disrupting system operations when the infected host is run.

  • Ransomware

    Why it's wrong here

    Ransomware is a type of malware designed to encrypt a victim's files or lock their computer system, demanding a ransom payment, typically in cryptocurrency, for decryption or access restoration. While some advanced variants may incorporate worm-like capabilities for initial spread (e.g., WannaCry), its primary function is data extortion, not self-replication as a core characteristic. Its delivery often relies on phishing emails, exploit kits, or other malware infections, rather than autonomous network propagation.

About these practice questions

This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.