NEW
Font size
WorksheetsT3 - Malicious Code
Total questions: 70
Worksheet time: 2hrs 45mins
Which of the following MOST likely describes the behavior of ransomware?
Collects keystrokes to steal credentials
Encrypts files and demands payment for decryption
Creates hidden administrator accounts
Self-replicates across networked systems
After a phishing email is opened, a message appears demanding Bitcoin to unlock files. Which immediate action should a technician take FIRST?
Pay the ransom to avoid data loss
Reboot the system in Safe Mode
Isolate the host from the network
Run a disk cleanup utility
Which network protocol weakness did the WannaCry outbreak exploit?
SMBv1
FTP
RDP
SNMP
Which of the following MOST likely represents malware that masquerades as legitimate software while installing a backdoor?
Worm
Rootkit
Trojan
Spyware
Which indicator MOST likely reveals a Trojan infection?
Spikes in broadcast traffic
Altered file extensions
New startup services or scheduled tasks
Sudden file encryption
A finance PC shows encrypted HTTPS traffic to rare domains overseas. Which malware type is MOST likely responsible?
Virus
Trojan
Spyware
Keylogger
Which malware type self-replicates without user action and can quickly saturate bandwidth?
Worm
Trojan
Virus
Logic Bomb
Which control MOST effectively prevents a worm outbreak from spreading?
Enforce egress filtering
Apply patches and segment networks
Train users on phishing awareness
Reboot affected hosts
Which malware type requires user execution of an infected file to spread?
Trojan
Virus
Worm
Rootkit
Which network symptom MOST likely indicates a worm infection?
New scheduled tasks
Abnormal outbound SMTP traffic
Frequent system reboots
Pop-up advertisements
Which of the following BEST describes spyware?
Encrypts files for ransom
Deletes system data
Silently collects user activity and credentials
Hijacks boot sectors
Which control MOST effectively mitigates spyware?
Disable macros in Office
Harden browsers and enforce least privilege
Enable SMBv1
Remove network segmentation
Software pre-installed by vendors that slows performance is BEST categorized as:
Worm
Spyware
Bloatware / PUP
Rootkit
Which mitigation MOST likely prevents unwanted bundled installations?
Segmentation
Safe-install choices and allow-listing
EDR telemetry
Encrypted DNS
Which malware captures keyboard input and stores it in plain text?
Spyware
Worm
Keylogger
Trojan
An analyst observes text files updating in C:\Temp as a user types. Which malware is MOST likely present?
Worm
Keylogger
Rootkit
Ransomware
A logic bomb can be BEST described as code that:
Encrypts files on a timer
Executes when specific conditions are met
Replicates across the network
Injects code into the OS kernel
Which historical incident involved a fired employee activating a logic bomb?
Tim Lloyd
Kevin Mitnick
Marcus Hutchins
Albert Gonzalez
Rootkits primarily attempt to:
Gain financial credentials
Hide malicious activity from detection tools
Spread automatically
Modify web browsers for ads
Which observation MOST likely indicates a rootkit?
Pop-up ads
Hidden processes invisible to Task Manager
Slow startup
Disabled print service
Which remediation step is MOST reliable for confirmed rootkit infections?
Run AV scan
Re-image from a clean source
Delete registry entries
Disable services
Which malware used digitally signed drivers to conceal industrial sabotage?
WannaCry
Zeus
Stuxnet
Emotet
Periodic encrypted DNS queries to rare domains from several hosts MOST likely indicate:
Ransomware propagation
Botnet command-and-control
Worm scanning
Virus infection
Which botnet architecture is MOST resilient against single-server takedowns?
Centralized
Layered
Peer-to-peer
Modular
A botnet performing crypto-mining primarily affects which security objective?
Confidentiality
Integrity
Availability
Non-repudiation
Which tool would MOST likely detect a worm’s lateral movement across subnets?
NetFlow analyzer
Hash calculator
DLP scanner
Password cracker
Which detection method MOST effectively identifies encrypted C2 traffic?
Signature-based IDS
Behavioral analytics and JA3 fingerprinting
Port blocking only
Static blacklists
Which malware goal is to deceive users into running malicious code disguised as useful software?
Worm
Trojan
Virus
Logic Bomb
Which security control MOST effectively prevents Trojans from email attachments?
Disable macros and enable secure mail filtering
Patch network devices
Segment internal subnets
Apply DNS filtering only
Malware that operates entirely in memory by abusing system tools is BEST described as:
Trojan
Worm
Fileless malware
Virus
Which indicator MOST likely reveals a keylogger dropped by a Trojan?
Unsigned kernel driver
Outbound spam traffic
Suspicious parent-child process chains
Browser DLL injection
Which mitigation MOST effectively limits a worm’s lateral spread after infection?
Email filtering
Network segmentation
Patch management
Application allow-listing
Which malware family commonly uses DLL injection or kernel manipulation to remain hidden?
Virus
Rootkit
Worm
Spyware
Why are immutable backups critical when mitigating ransomware?
Improve boot speed
Prevent alteration or deletion of recovery data
Reduce false positives
Automate drive encryption
Which log pattern MOST likely suggests active C2 beaconing?
Repeated failed logins
Regular timed connections to aging domains
USB mount events
Localhost DNS queries
Analysts determine that a PowerShell script executed from a temporary folder immediately after a phishing email was opened. Which phase of the attack lifecycle does this MOST likely represent?
Initial Access
Execution
Persistence
Impact
Which control would MOST likely prevent malware from maintaining persistence through registry run keys?
Secure Boot
EDR registry monitoring
DNS filtering
Immutable backups
Privilege escalation attempts exploiting unsigned drivers can BEST be mitigated by:
Enforcing driver-signing requirements
Network segmentation
User-training refreshers
Disabling Office macros
An analyst observes the process chain winword.exe → powershell.exe → cmd.exe on a host. This activity MOST likely indicates which attack technique?
Living-off-the-land execution
Lateral movement
File infection
DNS tunneling
Applying the principle of least privilege MOST directly mitigates which phase of an attack?
Privilege Escalation
Persistence
Execution
Impact
Which single control MOST effectively limits data exfiltration during the impact phase of an attack?
DNS sinkholing
Network segmentation with egress filtering
Disabling macros
Patch management
Packed executables with random filenames in %AppData% MOST likely indicate which evasion technique?
Code obfuscation/packing
Lateral movement
Keylogging
C2 beaconing
Which malware type MOST commonly modifies system utilities to conceal malicious processes?
Trojan
Virus
Rootkit
Worm
Which practice MOST effectively prevents logic bombs in production software?
Code review and change-control procedures
Behavior analytics
Secure Boot
DLP monitoring
Correlating synchronized beacon timing across multiple hosts would MOST likely detect:
Peer-to-peer botnet activity
Drive-by downloads
Macro-based malware
Rootkit infection
Which component of a malware campaign maintains communication with attacker infrastructure?
Loader
Dropper
Command-and-Control (C2) channel
Exploit kit
Which control combination MOST effectively prevents reinfection following a ransomware incident?
Patch management and immutable backups
Enable SMBv1 and host firewall
User awareness training only
DNS filtering only
Spyware that injects DLLs into browser processes is BEST detected through:
Application allow-listing
Browser hardening
Memory analysis and EDR telemetry
Network segmentation
Why are PUPs considered a potential security risk even when not directly malicious?
They disable antivirus software
They degrade performance and expand attack surface
They encrypt drives for ransom
They replicate autonomously
Which key distinction differentiates a worm from a Trojan?
Worms require user execution
Worms self-replicate automatically
Trojans spread autonomously
Trojans exploit kernel drivers
Which toolset provides the MOST complete visibility into C2 beacon behavior?
EDR integrated with SIEM correlation
Backup and restore utilities
Group Policy Editor
DLP endpoint agent
A malicious macro creates a hidden Windows service that runs after reboot. This action MOST likely represents which attack phase?
Initial access
Persistence
Privilege escalation
Lateral movement
Which configuration change MOST effectively mitigates “living-off-the-land” fileless attacks?
Disable unused admin tools and restrict PowerShell
Increase AV signature updates
Enable legacy SMBv1
Force password rotation
Which event MOST likely marks the impact stage of a ransomware attack?
Creation of a scheduled task
File encryption and ransom note display
Exploitation of a browser plugin
Outbound beacon to C2
Which control MOST effectively prevents privilege escalation through vulnerable drivers?
Timely patch management
Network segmentation
DNS sinkholing
Macro disablement
TLS traffic with mismatched SNI and JA3 signatures MOST likely indicates:
C2 tunneling activity
Normal web browsing
File transfer
Email communication
Which of the following MOST likely explains why network segmentation is critical once a worm is detected on a corporate subnet?
It hides the malware’s signatures from antivirus scans
It restricts the worm’s ability to propagate laterally
It prevents installation of rootkits on domain controllers
It removes keyloggers from infected systems
Which well-known malware specifically targeted industrial control systems to cause physical damage?
Zeus
Stuxnet
Emotet
MyDoom
Which technique do many botnets use to remain reachable even after security teams block their domains?
Domain Generation Algorithms (DGA)
MAC address spoofing
ARP poisoning
VPN tunneling
Which combination of controls MOST effectively limits ransomware damage and prevents botnet persistence?
Offline backups + least privilege + egress filtering
Macro disablement only
Browser extensions only
Password rotation only
Multiple endpoints show encrypted files and ransom notes, but backups are intact. Which immediate coordinated action should responders take FIRST?
Power off all user systems
Disconnect infected hosts from the network
Pay the ransom to recover quickly
Run System Restore
Users report browser redirects and credential theft. EDR logs show browserhelper.dll loading at startup. Which malware type is MOST likely present?
Spyware
Worm
Keylogger
Trojan
A workstation contacts a known phishing domain every 90 seconds while idle, and CPU usage stays high. Which issue is MOST likely occurring?
Worm scanning
Botnet beaconing
Logic bomb activation
Rootkit driver load
During forensics, investigators find a disabled service created five days before a ransomware detonation that auto-enabled on the attack day. Which artifact does this BEST represent?
Rootkit driver
Logic bomb trigger
Worm payload
Bootloader virus
An employee installs a “free PDF converter,” after which pop-ups and slow performance begin. What infection vector and malware type are MOST likely?
Drive-by / Rootkit
Bundled installer / PUP
Phishing / Ransomware
Macro / Trojan
After removing a rootkit, EDR still flags unsigned drivers loading at boot. Which remediation step should be taken NEXT?
Delete temporary files
Re-image the system from a trusted source
Disable the network adapter
Rename suspect drivers
A phishing email delivers a dropper that installs Emotet, which then spreads laterally and steals credentials. Which control could have prevented the initial compromise?
Email filtering and macro restrictions
Immutable backups
DNS sinkholing
Network segmentation
A network admin notices hundreds of outbound DNS requests to random .ru domains. Which mitigation should be implemented FIRST?
DNS filtering with blocklists
Update printer firmware
Increase password length
Enable guest Wi-Fi
Behavior-based analytics flag hosts making abnormal beacon patterns and automatically isolate them. This protection primarily disrupts which attack phase?
Defense Evasion
Command and Control
Impact
Persistence
A developer’s maintenance script deletes production files when a date variable resets to zero. Which preventative measure would MOST effectively catch this error before deployment?
Secure coding standards and peer code review
Driver signing requirements
DNS tunneling detection
Password complexity policy
