312-50 exam dumps

312-50 practice question 168 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 168

Single answer▪ Virus and Worm Concepts

During an internal security assessment, you observe that several Windows workstations begin scanning random internal IP addresses and creating a high volume of outbound connections without any user interaction. Initial triage shows no evidence that users opened suspicious attachments, but multiple hosts became infected within minutes after one unpatched machine was connected to the network. Which conclusion BEST explains this behavior?

  1. A

    The environment is most likely affected by a worm that self-propagates by exploiting network vulnerabilities.

  2. B

    The environment is most likely affected by a traditional file-infecting virus that requires users to execute infected files on each host.

  3. C

    The activity is most consistent with a logic bomb triggered by a scheduled task on all systems at the same time.

  4. D

    The behavior indicates a spyware infection whose primary function is to monitor browsing activity rather than spread laterally.

Show answer and explanation

Correct answer: A

Explanation

The best answer is the worm option because worms differ from viruses primarily in their ability to self-propagate without requiring a user to execute an infected file on each victim system. In practical incident response, rapid infection of multiple hosts, autonomous port or IP scanning, and exploitation of unpatched services are strong indicators of worm activity. This distinction is foundational in CEH malware concepts: viruses usually require a host file and some form of execution, whereas worms are standalone and spread over networks. Defensive best practices from organizations such as CISA, NIST, and major vendor incident guidance emphasize prompt patching, network segmentation, IDS/IPS monitoring for scanning behavior, and isolation of infected hosts when worm-like activity is observed.

  • A. Correct.

    Correct. A worm is malware designed to self-replicate and spread across networks without requiring user action on each target. The key indicators in the scenario are rapid propagation, infection after an unpatched host joined the network, and autonomous scanning of internal IP addresses. This is consistent with classic worm behavior such as exploiting vulnerable services and moving laterally at network speed.

  • B. Incorrect.

    Incorrect. A traditional virus typically depends on a host file or user action, such as opening an infected executable, document, or macro-enabled file, to spread. While some viruses can spread widely, the scenario specifically emphasizes no user interaction and very fast infection across multiple systems after one vulnerable machine connected, which points more strongly to a worm than a classic file-infecting virus.

  • C. Incorrect.

    Incorrect. A logic bomb is malicious code that activates when a specific condition or time is met, but it is not defined by self-replication or network-based propagation. The simultaneous or near-simultaneous infection pattern here is better explained by automated scanning and exploitation, not by a pre-planted trigger existing independently on many systems.

  • D. Incorrect.

    Incorrect. Spyware is generally focused on surveillance, credential theft, or data collection. Although some spyware may communicate externally, it does not typically explain rapid self-directed internal scanning and near-immediate spread to multiple hosts. The lateral propagation behavior in this scenario is the more important clue, and that is characteristic of a worm.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam