wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

What is a Trojan? And Its Indications

Total questions: 36

Worksheet time: 18mins

Name
Class
Date
1.

Which statement best defines a computer Trojan as described in the material?

a)

A self-replicating program that spreads without user action

b)

A program in which malicious or harmful code is contained inside an apparently harmless program or data, later gaining control and causing damage

c)

A security tool that prevents unauthorized access by encrypting data

d)

A network monitoring utility used to detect malware

2.

According to the origin story used in the text, the term "Trojan" is inspired by which event from Greek mythology?

a)

The voyage of Odysseus

b)

The battle of Thermopylae

c)

The Trojan War involving a giant wooden horse used to infiltrate Troy

d)

The creation of Mount Olympus

3.

What typically activates a Trojan on a victim’s system?

a)

Automatic OS updates

b)

User performing certain predefined actions, such as unintentionally installing malicious software or clicking a malicious link

c)

Physical access by the attacker to the machine

d)

A server-side script running on the network

4.

Which is NOT listed as a way hackers use Trojans?

a)

Disable firewalls and antivirus

b)

Record screenshots, audio, and video of a victim’s PC

c)

Use the victim’s PC as a botnet to perform DDoS attacks

d)

Automatically patch the victim’s OS with security updates

5.

Which method describes how attackers may propagate Trojans using victims as intermediaries?

a)

By forcing users to change their passwords frequently

b)

By wrapping malicious code to legitimate programs and using a victim’s computer to commit illegal DoS attacks

c)

By disabling internet connectivity entirely

d)

By installing only signed drivers

6.

Once a Trojan infects a system, what level of privileges does it typically operate with?

a)

Higher than kernel level

b)

Lower than guest account

c)

The same level of privileges as the victim, and it may exploit vulnerabilities to elevate privileges

d)

No privileges until approved by the administrator

7.

Which network scenario increases risk if compromised by a Trojan, according to the text?

a)

Systems using multi-factor authentication only

b)

Systems that transmit passwords over shared networks in clear text or trivially encrypted form

c)

Air-gapped systems without network connectivity

d)

Networks with only IPv6 addresses

8.

Which of the following is an indication of a Trojan attack related to display behavior?

a)

The monitor physically turns off

b)

The computer screen flips upside-down, is inverted, or displays everything backward

c)

Only brightness reduces to minimum

d)

The resolution changes to 4K

9.

Which symptom indicates possible interference with system controls by a Trojan?

a)

The keyboard backlight turns blue

b)

The mouse cursor moves by itself or clicks icons uncontrollably

c)

USB ports become faster

d)

Battery life improves

10.

Which set best groups multiple signs of a Trojan attack affecting system components?

a)

Antivirus automatically updates; browser loads faster; OS boots quicker

b)

Antivirus is disabled and data is corrupted or deleted; Task Manager is disabled; unusual high CPU or memory usage

c)

New fonts appear; printer toner is low; wallpaper remains unchanged

d)

System fan becomes louder; external speakers disconnect; screen saver stays default

11.

Which of the following is a malicious purpose for which attackers deploy Trojans?

a)

Installing operating system updates

b)

Generating fake traffic to perform DoS attacks

c)

Encrypting data for secure communication

d)

Training users on security best practices

12.

In the context of Trojan activity, what does the "listening" state indicate?

a)

The system is actively blocking all ports

b)

The system waits on a port number to connect to another system

c)

The port is reserved for hardware devices only

d)

The Trojan has completed data transfer and shut down

13.

Which sensitive information is specifically mentioned as targeted by Trojans using keyloggers?

a)

Biometric fingerprints

b)

Credit card information useful for domain registration and shopping

c)

Encrypted VPN keys

d)

Source code repositories

14.

According to the table of common ports, which Trojan is associated with port 25?

a)

WinCrash

b)

Antigen

c)

Hackers Paradise

d)

BadPatch

15.

What is a possible post-compromise use of infected devices as described?

a)

Serving as botnets to launch DDoS attacks, send spam emails, or mine cryptocurrencies

b)

Automatic patch management for enterprises

c)

Hosting secure backups for users

d)

Running intrusion detection systems

16.

Which ports are listed for Emotet in the table?

a)

21

b)

5321

c)

6666

d)

6969

17.

Which statement best describes network ports as used by Trojans?

a)

Ports are only physical connectors on hardware

b)

Ports within the OS are software entry/exit points for application traffic, some application-specific or process-specific

c)

Ports can only be used by web browsers

d)

Ports are random numbers with no association to traffic types

18.

Which Trojan commonly uses port 7000?

a)

Remote Grab

b)

NetMonitor

c)

Net Spy

d)

Qaz

19.

Port 7777 is associated with which Trojan?

a)

BADCALL

b)

GodMsg

c)

ICKiller

d)

Ptakks

20.

Which Trojan is mapped to port 8787/54321?

a)

BackOffice 2000

b)

NetBus

c)

GirlFriend 1.0

d)

Delta

21.

Which Trojan pair is listed for port 20034/1120?

a)

Back Orifice / Deep BO

b)

NetBus 2.0, Beta-NetBus 2.01

c)

GabanBus, NetBus

d)

Hack’99 KeyLogger

22.

DeepThroat is shown to use which ports?

a)

2140

b)

2140/3150

c)

31339

d)

31666

23.

Which category best describes malware that provides full remote control over a victim system?

a)

Backdoor Trojans

b)

Remote Access Trojans

c)

Botnet Trojans

d)

Command Shell Trojans

24.

Which statement best describes a Remote Access Trojan (RAT)?

a)

A benign remote administration tool used for IT support

b)

Malware that provides attackers full control over a victim’s system, enabling remote access to files and activities

c)

A firewall rule that blocks unauthorized ports

d)

A hardware device used to sniff network traffic

25.

In the example scenario, how does Jason establish control over Rebecca’s computer?

a)

By sending a phishing email with a malicious macro that opens Port 25

b)

By infecting the system with server.exe and planting a reverse connecting Trojan that connects through Port 80

c)

By exploiting a misconfigured VPN to gain shell access on Port 443

d)

By physically inserting a USB drive and copying RAT binaries

26.

Which capability is commonly associated with RATs as described in the material?

a)

Encrypting hard drives to demand ransom only

b)

Performing screen and camera capture, keylogging, file access, and registry management

c)

Providing automatic system patching and antivirus updates

d)

Limiting network downloads to prevent malware spread

27.

What notable shift in attack vectors did recent analyses report for Remcos RAT distribution?

a)

Use of ISO images

b)

Use of virtual hard disk (.vhd) files with multifaceted capabilities

c)

Exclusive use of malicious browser extensions

d)

Transition to hardware-based implants

28.

According to the extracted VHD file flow diagram, which sequence correctly reflects the layered execution chain?

a)

AMSI Reaper → PowerShell script → PNG to PDF → Task Schedule → VB script → Remcos RAT → .NET binary

b)

PNG to PDF → AMSI Reaper → VB script (base64 decode) → PowerShell script → Download elena.png → Image base64 decode → .NET DLL

c)

PowerShell script → AMSI Bypass → VB Script → Direct RAT execution without downloads

d)

Task Schedule → Immediate RAT execution bypassing any scripts

29.

Which PowerShell behavior is specifically highlighted in the screenshot showing the download of a PDF disguised as PNG?

a)

Writing registry keys to disable Defender directly

b)

Using Invoke-WebRequest to download a file and decoding base64 data to output a PDF

c)

Scheduling a task that runs a batch file every hour

d)

Running a WMI query to enumerate installed software

30.

Which item from the list is an example of an additional RAT mentioned in the material?

a)

Wireshark

b)

Parallax RAT

c)

OpenSSH

d)

Burp Suite

31.

What is a common method used by attackers to disguise Trojans?

a)

Using strong encryption to hide the payload

b)

Creating a separate operating system for execution

c)

Utilizing cloud storage for distribution

d)

Embedding malicious code in legitimate software

32.

Which of the following is a sign that a Trojan may be present on a system?

a)

Improved system performance

b)

Unexpected pop-up ads and browser redirects

c)

Increased battery life on laptops

d)

Frequent system updates

33.

What type of data is often targeted by Trojans for exfiltration?

a)

Software installation logs

b)

System configuration files

c)

User credentials and personal information

d)

Temporary internet files

34.

What type of malware is designed to capture keystrokes and send them to an attacker?

a)

Spyware

b)

Worms

c)

Keyloggers

d)

Adware

35.

Which of the following is a common technique used to deliver Trojans to unsuspecting users?

a)

Direct installation via USB

b)

Bundling with legitimate software

c)

Using hardware backdoors

d)

Only through email attachments

36.

What is the primary goal of a Trojan horse in a cybersecurity context?

a)

To protect against malware

b)

To improve user experience

c)

To enhance system performance

d)

To provide unauthorized access to the system