312-50 exam dumps

312-50 practice question 166 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 166

Single answer▪ Virus and Worm Concepts

A security team is investigating a sudden outbreak in a corporate network. Several Windows hosts began generating high volumes of outbound SMB traffic to random internal IP addresses, and new systems became affected even though users reported not opening suspicious email attachments or downloading files. The malware appears to spread without user interaction by exploiting a vulnerability in a network service. Which type of malware best fits this behavior?

  1. A

    A file-infecting virus that requires a user to execute an infected program on each host

  2. B

    A worm that self-replicates across the network by exploiting vulnerable services

  3. C

    A macro virus embedded in office documents that spreads only when users open infected files

  4. D

    A Trojan horse disguised as legitimate software that depends on social engineering for installation

Show answer and explanation

Correct answer: B

Explanation

The correct answer is a worm because the malware spreads independently across the network by exploiting a vulnerable service, without requiring users to open files or run infected applications. This is a core distinction between worms and viruses in CEH objectives: a virus generally needs a host file and some form of user execution, while a worm is self-contained and can propagate automatically. High-volume SMB scanning and rapid host-to-host spread are classic worm indicators in Windows environments. From a defensive and investigative perspective, this behavior is consistent with guidance from organizations such as CISA and Microsoft, which emphasize prompt patching of exposed services, segmentation, IDS/IPS monitoring for lateral movement, and isolation of infected hosts when worm-like activity is detected.

  • A. Incorrect.

    Incorrect. A file-infecting virus typically attaches itself to executable files or other host files and usually needs user action, such as running an infected program, to propagate. The scenario specifically states that systems were infected without users opening files or downloading software, which does not match classic virus behavior.

  • B. Correct.

    Correct. A worm is designed to self-replicate and spread autonomously, often by scanning for and exploiting vulnerable network services such as SMB. The key indicators in the scenario are rapid lateral spread, network-based propagation, exploitation of a service vulnerability, and no dependency on user interaction. This aligns with well-known worm behavior seen in incidents such as WannaCry, which propagated via SMB-related exploitation.

  • C. Incorrect.

    Incorrect. A macro virus spreads through document files and depends on users opening infected documents and enabling macro execution. In this case, there is no evidence of document-based delivery or user-triggered execution, and the observed SMB scanning behavior points to network-service exploitation rather than document infection.

  • D. Incorrect.

    Incorrect. A Trojan horse relies on tricking users into installing or executing malicious software by presenting it as legitimate. While Trojans may later download other payloads, the defining behavior in this scenario is autonomous propagation across hosts through a network vulnerability, which is characteristic of a worm, not a Trojan.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam