CEH Practice Question: Malware, Social Engineering and Network Attacks
Which THREE of the following are indicators that a system may be infected with a backdoor Trojan? (Select three)
⚠ Common exam trap
The trap here is that candidates may mistake generic system performance issues (like high CPU usage) for malware indicators, when CEH focuses on network-level anomalies (unexpected ports, outbound connections) as more specific signs of a backdoor Trojan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unexpected network traffic on ports typically used for remote administration
Option A is correct because backdoor Trojans commonly open or connect to remote-administration ports (e.g., TCP 3389 for RDP, 22 for SSH, or 4444/31337 for malware C2) to give attackers remote control, so unexpected traffic on such ports signals compromise. Option C is correct because a backdoor typically installs itself as a hidden or unauthorized background process (often masquerading as a legitimate service) to maintain persistence and accept attacker commands. Option E is correct because backdoors beacon out to attacker-controlled command-and-control servers, producing unusual outbound connections to unknown or suspicious IP addresses. Option B is not a reliable indicator because high CPU usage by one process is more characteristic of cryptominers, fork bombs, or buggy applications than of a stealthy backdoor, which usually minimizes resource use to avoid detection. Option D is not a reliable indicator because DNS queries to known legitimate sites are normal user or system activity and do not by themselves suggest a backdoor, which would more likely resolve unknown or algorithmically generated domains.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Unexpected network traffic on ports typically used for remote administration
Why this is correct
Unexpected traffic on ports like TCP 3389 (RDP), TCP 22 (SSH), or TCP 23 (Telnet) is suspicious because these ports are typically used for remote administration. If such traffic appears without a legitimate reason, it may indicate a backdoor Trojan that has opened that port for remote access.
- ✗
Persistent high CPU usage by a single process
Why it's wrong here
Sustained CPU load from one process is generic malware behaviour, not a backdoor-specific indicator; legitimate services and cryptominers produce identical symptoms. Backdoor Trojans typically manifest as unexpected listening ports, anomalous outbound connections, or disabled logging. High CPU would fit a resource-exhaustion or cryptojacking scenario instead.
- ✓
Unauthorized processes running in the background
Why this is correct
Unauthorised background processes satisfy the stem's requirement for a backdoor Trojan indicator because a backdoor maintains persistent remote access by executing hidden processes, often masquerading as legitimate services. These processes listen for attacker commands or beacon outbound, consuming resources and appearing in task listings without user initiation.
- ✗
Increased number of DNS queries to known legitimate sites
Why it's wrong here
Queries to known legitimate sites are ordinary resolution traffic, not evidence of compromise; a backdoor usually beacons to attacker-controlled infrastructure or uses DNS tunnelling to unusual domains. This option would suit baselining normal resolver behaviour, whereas Trojan detection relies on anomalous destinations, encoded query patterns, or unexpected resolver changes.
- ✓
Unusual outbound connections to unknown IP addresses
Why this is correct
Unusual outbound connections to unknown IP addresses reveal a backdoor Trojan's command-and-control channel, satisfying the stem's requirement for infection indicators. Unlike legitimate traffic, these connections often target odd ports or foreign hosts at irregular intervals, reflecting beaconing behaviour. This distinguishes covert exfiltration from normal network activity.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.