312-50 exam dumps

312-50 practice question 157 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 157

Single answer▪ Malware Concepts

During an internal security assessment, a Windows workstation begins making periodic outbound HTTPS connections to an unfamiliar domain every 60 seconds. The process responsible is running from the user's AppData\Roaming folder under a name similar to a legitimate Windows component, and it automatically restarts after the user logs off and back on. The executable does not spread to other hosts or modify boot records, but it appears to wait for remote instructions and can download additional payloads. Based on these observed behaviors, which type of malware most accurately describes the threat?

  1. A

    A worm

  2. B

    A Trojan acting as a bot/client in a botnet

  3. C

    A boot sector virus

  4. D

    A ransomware dropper

Show answer and explanation

Correct answer: B

Explanation

The best answer is a Trojan acting as a bot/client in a botnet. In real-world malware analysis and CEH exam scenarios, analysts distinguish malware families by behavior: worms self-propagate, boot sector viruses target startup sectors, ransomware focuses on extortion through encryption or system lockout, while bots commonly maintain persistence and communicate with a command-and-control (C2) server to receive tasks or download payloads. The indicators here, regular outbound beaconing over HTTPS, deceptive process naming, execution from AppData\Roaming, and persistence across user logon sessions, align strongly with a Trojanized bot client. This matches common guidance from incident response best practices such as those described by NIST malware incident handling recommendations, where recurring outbound connections and remote tasking are key indicators of C2-based malware.

  • A. Incorrect.

    Incorrect. A worm is primarily characterized by self-replication and autonomous propagation across networks or systems without requiring user action. In this scenario, there is no evidence that the malware is scanning for other hosts or spreading laterally. The periodic outbound command-and-control style communication is more consistent with a bot or remote-access malware than with a worm.

  • B. Correct.

    Correct. The malware is exhibiting classic Trojan/bot behavior: disguising itself as a legitimate process, persisting in a user profile location, beaconing to an external command-and-control server at regular intervals, and being capable of receiving instructions and downloading additional payloads. In CEH context, a bot is commonly a compromised host under remote control, and malware installed as a Trojan often serves as the bot client.

  • C. Incorrect.

    Incorrect. A boot sector virus infects the boot sector or master boot record and is typically associated with execution during system startup before the operating system fully loads. The scenario explicitly states that the malware does not modify boot records, which rules out this category. Choosing this option would reflect confusion between persistence mechanisms and boot-level infection.

  • D. Incorrect.

    Incorrect. A ransomware dropper would primarily be associated with delivering ransomware for file encryption or extortion-related payloads. Although droppers can download additional malware, the described steady beaconing and waiting for commands are more indicative of command-and-control bot activity than a ransomware-specific delivery mechanism. There is also no evidence of encryption, ransom notes, or data denial effects.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam