HomeSubjectsUniversityBlogAbout

Malware & Attacks

Topic in Cyber Security

180 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Malware is malicious software, such as viruses, worms, trojans, ransomware and spyware, designed to damage systems, steal data or give attackers control. Classification questions hinge on details, for example a worm spreads on its own while a virus needs a host file. You should recognize droppers, rootkits, keyloggers, logic bombs and fileless malware, and how botnets use command-and-control servers and domain generation algorithms to evade blocking. Attack techniques include phishing, spear phishing, social engineering, brute force versus credential stuffing, and zero-day exploits. Advanced persistent threats and their lifecycle, plus signature versus heuristic antivirus detection, finish the set.

Below are 30 practice questions from a pool of 180 Malware & Attacks MCQs, one of 16 topics in Cyber Security. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

Malware & AttacksEasy

Q1. What is spyware?

  1. A.Software that secretly monitors and collects user information without consent✓ Correct
  2. B.A security tool for scanning and detecting vulnerabilities
  3. C.A telescope used for astronomical observation used in enterprise computing environments
  4. D.A standard web browser for accessing internet sites

Explanation

Spyware secretly monitors user activity and collects personal information without consent.

Report an error in this question

Malware & AttacksEasy

Q2. What is malware?

  1. A.A physical hardware component inside computer systems
  2. B.Software intentionally designed to cause damage to a computer, server, or network✓ Correct
  3. C.Legitimate helpful software designed for user productivity
  4. D.An operating system for managing system resources used in enterprise computing environments

Explanation

Malware is any software intentionally designed to cause damage, disruption, or unauthorized access.

Report an error in this question

Malware & AttacksEasy

Q3. What is a Trojan horse in computing?

  1. A.A physical hardware component used in computing infrastructure
  2. B.Malware disguised as legitimate software to trick users into installing it✓ Correct
  3. C.An antivirus program designed to detect known threats
  4. D.A wooden horse artifact from ancient Greek history

Explanation

A Trojan disguises itself as legitimate software to deceive users into installing it.

Report an error in this question

Malware & AttacksEasy

Q4. What is adware?

  1. A.A security program designed to protect against malware
  2. B.An advertising company that creates marketing campaigns
  3. C.Software that automatically displays or downloads unwanted advertisements✓ Correct
  4. D.A helpful tool for managing and organizing digital files

Explanation

Adware automatically displays unwanted advertisements and can track browsing habits.

Report an error in this question

Malware & AttacksEasy

Q5. What is a computer worm?

  1. A.A physical hardware component used in computing infrastructure
  2. B.Self-replicating malware that spreads across networks without needing a host program✓ Correct
  3. C.A software application used for enterprise computing operations
  4. D.A hardware component inside wireless networking routers

Explanation

A worm spreads independently across networks without needing to attach to a host program.

Report an error in this question

Malware & AttacksEasy

Q6. What is ransomware?

  1. A.Malware that encrypts files and demands payment for the decryption key✓ Correct
  2. B.Free and open-source software available for download
  3. C.A backup tool for creating copies of important data
  4. D.An antivirus update that patches known vulnerabilities

Explanation

Ransomware encrypts files and demands a ransom payment in exchange for the decryption key.

Report an error in this question

Malware & AttacksEasy

Q7. What is a computer virus?

  1. A.A written record or logbook for tracking daily operational activities
  2. B.Malicious code that attaches to programs and replicates when the host program runs✓ Correct
  3. C.A routine system update for improving stability used in enterprise computing environments
  4. D.A self-replicating strain of malicious software targeting systems

Explanation

A computer virus attaches to legitimate programs and replicates by modifying other programs.

Report an error in this question

Malware & AttacksMedium

Q8. What is a keylogger?

  1. A.A tool for managing and organizing cryptographic keys
  2. B.Software or hardware that records keystrokes to capture sensitive information✓ Correct
  3. C.A software application used for enterprise computing operations
  4. D.A cryptographic algorithm used for protecting sensitive data

Explanation

A keylogger records every keystroke to capture passwords, credit card numbers, and other sensitive data.

Report an error in this question

Malware & AttacksMedium

Q9. What is a botnet?

  1. A.A helpful automated robot network for task assistance used in enterprise computing environments
  2. B.A chat bot service providing automated customer support used in enterprise computing environments
  3. C.A network monitoring tool for tracking bandwidth utilization
  4. D.A network of compromised computers controlled remotely for coordinated malicious activities✓ Correct

Explanation

A botnet is a collection of infected devices controlled by an attacker to perform coordinated attacks.

Report an error in this question

Malware & AttacksMedium

Q10. What is a rootkit?

  1. A.A disk utility for managing storage partitions used in enterprise computing environments
  2. B.Malware designed to gain unauthorized root-level access and hide its presence✓ Correct
  3. C.A legitimate system administration tool for configuration
  4. D.A standard operating system boot loader for initialization

Explanation

A rootkit provides continued privileged access while actively hiding its presence.

Report an error in this question

Malware & AttacksEasy

Q11. What is a phishing attack?

  1. A.A routine security scan assessing system vulnerabilities used in enterprise computing environments
  2. B.A standard network communication protocol for data transmission
  3. C.A recreational fishing technique using specialized gear used in enterprise computing environments
  4. D.A social engineering attack using deceptive messages to trick victims into revealing sensitive information✓ Correct

Explanation

Phishing uses fraudulent communications that appear from trusted sources to trick recipients.

Report an error in this question

Malware & AttacksEasy

Q12. What is a Denial of Service (DoS) attack?

  1. A.A network upgrade that improves bandwidth and throughput used in enterprise computing environments
  2. B.Refusing customer service in a retail environment across computing environments
  3. C.A software application used for enterprise computing operations
  4. D.An attack that overwhelms a system with traffic to make it unavailable to legitimate users✓ Correct

Explanation

A DoS attack floods a target with excessive traffic, making it unavailable to legitimate users.

Report an error in this question

Malware & AttacksMedium

Q13. How does a DDoS attack differ from DoS?

  1. A.DDoS attacks are generally considered less dangerous than standard single-source DoS attacks
  2. B.DDoS uses multiple compromised systems to flood the target, making it harder to mitigate✓ Correct
  3. C.They are functionally identical attack frameworks with no meaningful differences between them
  4. D.DoS attacks typically use significantly more compromised systems than DDoS attacks

Explanation

DDoS originates from many compromised systems simultaneously, making it harder to block.

Report an error in this question

Malware & AttacksEasy

Q14. What is the best defense against malware?

  1. A.Completely avoiding and never using a computer at all
  2. B.Only using free open-source software for all tasks
  3. C.Permanently disconnecting the system from internet access
  4. D.Using updated antivirus software and practicing safe computing habits✓ Correct

Explanation

The best defense combines updated antivirus software, regular updates, and user awareness.

Report an error in this question

Malware & AttacksMedium

Q15. What is social engineering?

  1. A.A software application suite used for enterprise computing operations and communications
  2. B.Building and developing social media networking platforms for public user interaction
  3. C.Psychological manipulation to trick people into making security mistakes or revealing information✓ Correct
  4. D.Engineering and designing interactive social interaction systems for enterprise organizations

Explanation

Social engineering exploits human psychology to manipulate people into divulging confidential information.

Report an error in this question

Malware & AttacksMedium

Q16. What is a drive-by download attack?

  1. A.A software application used for enterprise computing operations
  2. B.A standard file transfer method between connected systems used in enterprise computing environments
  3. C.Downloading files while driving in a moving vehicle
  4. D.Automatic download of malware when visiting a compromised website without user interaction✓ Correct

Explanation

A drive-by download automatically installs malware when visiting a compromised website.

Report an error in this question

Malware & AttacksMedium

Q17. What is a watering hole attack?

  1. A.A water cooling attack damaging hardware cooling systems
  2. B.Attacking municipal water supply infrastructure systems
  3. C.Compromising websites frequently visited by a targeted group to infect their computers✓ Correct
  4. D.A network flooding attack using volumetric traffic used in enterprise computing environments

Explanation

A watering hole attack compromises websites commonly visited by a specific target group.

Report an error in this question

Malware & AttacksMedium

Q18. What is fileless malware?

  1. A.A clean program verified by security code audit analysis
  2. B.Malware that operates without any source code at all
  3. C.Malware that operates entirely in memory without writing files to disk✓ Correct
  4. D.A type of antivirus program for real-time scanning

Explanation

Fileless malware resides in memory and uses legitimate system tools to execute malicious activities.

Report an error in this question

Malware & AttacksMedium

Q19. What are indicators of compromise (IOCs)?

  1. A.Performance metrics for measuring system throughput
  2. B.Signs indicating system improvement and optimization
  3. C.Software licensing keys for verifying installations
  4. D.Observable artifacts or evidence suggesting a system has been breached✓ Correct

Explanation

IOCs are forensic evidence like unusual IP connections or modified files indicating a potential breach.

Report an error in this question

Malware & AttacksMedium

Q20. What is a man-in-the-middle (MITM) attack?

  1. A.A professional mediator in business negotiations within modern computing environments
  2. B.A software application used for enterprise computing operations
  3. C.An attack where the attacker secretly intercepts and possibly alters communication between two parties✓ Correct
  4. D.A proxy server that forwards requests between systems used in enterprise computing environments

Explanation

In a MITM attack, the attacker intercepts and potentially modifies communication without either party knowing.

Report an error in this question

Malware & AttacksHard

Q21. What is a polymorphic virus?

  1. A.A virus designed for running on multiple hardware platforms
  2. B.A virus that infects only once and does not replicate further
  3. C.Malware that changes its code signature each time it replicates to evade detection✓ Correct
  4. D.A benign virus that enhances system security posture overall

Explanation

Polymorphic malware mutates its code while maintaining functionality to evade signature-based detection.

Report an error in this question

Malware & AttacksHard

Q22. What is an APT lifecycle?

  1. A.A system update cycle for deploying maintenance patches within modern computing environments
  2. B.A backup schedule for creating regular recovery snapshots for managing enterprise data resources
  3. C.A multi-stage attack process involving reconnaissance, initial access, persistence, lateral movement, and exfiltration✓ Correct
  4. D.A standard software development lifecycle methodology used in enterprise computing environments

Explanation

APT lifecycle involves reconnaissance, compromise, persistence, escalation, lateral movement, and exfiltration.

Report an error in this question

Malware & AttacksHard

Q23. What is a supply chain attack?

  1. A.A written record or logbook for tracking daily operational activities
  2. B.An attack compromising a trusted vendor or software update mechanism to distribute malware✓ Correct
  3. C.A procurement process for purchasing IT equipment used in enterprise computing environments
  4. D.Attacking physical supply chains and logistics routes

Explanation

Supply chain attacks target trusted vendors, inserting malicious code into legitimate software.

Report an error in this question

Malware & AttacksHard

Q24. What is living-off-the-land (LOTL) technique?

  1. A.Environmental computing initiatives for reducing power usage
  2. B.A green IT practice focused on sustainable computing used in enterprise computing environments
  3. C.Agricultural computing systems for managing farming operations
  4. D.Using legitimate system tools already present on the target system to carry out malicious activities✓ Correct

Explanation

LOTL techniques use legitimate pre-installed tools like PowerShell for malicious purposes to avoid detection.

Report an error in this question

Malware & AttacksHard

Q25. What is a logic bomb?

  1. A.Malicious code that remains dormant until triggered by a specific condition like a date or event✓ Correct
  2. B.A physical hardware component used in computing infrastructure
  3. C.A written record or logbook for tracking daily operational activities
  4. D.A software application used for enterprise computing operations

Explanation

A logic bomb activates when specific conditions are met, such as a particular date or event.

Report an error in this question

Malware & AttacksHard

Q26. What is DNS tunneling used for in attacks?

  1. A.A DNS caching technique for reducing query response time used in enterprise computing environments
  2. B.Encoding data within DNS queries to establish a covert communication channel bypassing firewalls✓ Correct
  3. C.A DNS optimization technique for faster name resolution used in enterprise computing environments
  4. D.Improving DNS resolution speed and performance latency

Explanation

DNS tunneling encodes non-DNS traffic within DNS queries, creating a covert channel for data exfiltration.

Report an error in this question

Malware & AttacksHard

Q27. What is command and control (C2) infrastructure?

  1. A.A network management tool used in enterprise network infrastructure
  2. B.The communication framework attackers use to maintain control over compromised systems✓ Correct
  3. C.A software development platform for building applications
  4. D.A military headquarters facility for coordinating operations

Explanation

C2 infrastructure is the system of servers and protocols attackers use to remotely control compromised systems.

Report an error in this question

Malware & AttacksHard

Q28. What is a metamorphic virus?

  1. A.A virus that migrates and spreads between different host operating systems and platforms
  2. B.A virus that executes only once on a system and then immediately self-terminates
  3. C.Malware that completely rewrites its own code with each iteration while maintaining functionality✓ Correct
  4. D.A benign virus variant that improves overall system security posture and performance

Explanation

Metamorphic malware completely rewrites its code with each propagation, making each copy unique.

Report an error in this question

Malware & AttacksHard

Q29. What is steganography in cyber attacks?

  1. A.A type of prehistoric dinosaur classification study used in enterprise computing environments
  2. B.A printing technique for high-resolution image output used in enterprise computing environments
  3. C.Hiding malicious data or communications within ordinary-looking files like images or audio✓ Correct
  4. D.A photography method for capturing wide-angle images used in enterprise computing environments

Explanation

Steganography hides secret data within ordinary files, allowing concealment of malicious payloads.

Report an error in this question

Malware & AttacksHard

Q30. What is the MITRE ATT&CK technique T1055 (Process Injection)?

  1. A.A standard software development pattern used for organizing code into modules
  2. B.A performance optimization technique for accelerating overall application speed
  3. C.A technique where malicious code is injected into the address space of a legitimate process✓ Correct
  4. D.A runtime debugging technique used for identifying and resolving code defects

Explanation

Process Injection involves injecting code into running processes to execute under their context and evade defenses.

Report an error in this question

Ready to test yourself on Malware & Attacks?

Take a timed quiz drawn from 180+ questions on this topic. No signup required — your progress saves in your browser.

Start Malware & Attacks Quiz