ExamShortcut

Cyber Security

🔒 Log in to track
high importance⚡ 8 shortcuts4 subtopics
All subtopics·Subtopic 1 of 4
⏱ 3 min read🧩 5 question types🎯 17 practice Q
The idea in one minute

Malware is short for malicious software. It is any program made to harm, steal or spy. Exam questions ask you to match a behaviour to a name. Learn the key difference: a virus needs a host file, a worm needs none and a trojan does not copy itself.

01

What malware is

Malware means malicious software. It is a program written to harm a computer, steal data or spy on a user. Questions test one skill: match the behaviour to the name.

MalwareKey behaviour
VirusAttaches to a file or program. Spreads when the file is run. Needs a host
WormCopies itself across a network. Needs no host file
Trojan horseHides inside useful-looking software. Does not copy itself
RansomwareLocks or encrypts files and demands money. WannaCry (2017) is an example
SpywareSecretly collects your information and sends it out
KeyloggerRecords every key you press, so it can catch passwords
AdwareShows unwanted advertisements
RootkitHides deep in the system and gives the attacker admin rights
BotnetMany infected "zombie" machines controlled together, often for spam or DDoS
Logic bombCode that sleeps until a date or event, then does its damage
02

Three pairs that exams mix

  1. Virus vs worm. A virus rides on a host file and waits for you to run it. A worm needs no host. It travels through the network alone.
  2. Trojan vs virus. A trojan never copies itself. It pretends to be useful and opens a back door from inside.
  3. Ransomware vs spyware. Ransomware holds your files hostage. Spyware quietly copies data and leaves everything in place.

Rule: Ask three things. Does it need a host? Does it copy itself? Does it demand money?

03

How malware arrives

  • Infected e-mail attachments and links.
  • Pirated software.
  • Infected USB drives.
  • Downloads from unsafe sites.
  • Fake pop-ups that say "your PC is infected".
04

Signs of infection

  • The computer runs unusually slowly.
  • Files are renamed or missing.
  • Programs open on their own.
  • The browser home page changes.
  • Pop-ups appear all the time.

Watch: One sign alone does not prove malware. Together they form the usual exam scenario.

05

Safe habits

Keep the operating system and antivirus updated. Do not open unknown attachments. Install software only from official sources. Take regular backups.

Example: A free game hides a program that lets a stranger control your PC. It does not copy itself. That is a trojan.

06

Question types you will see

Each type: how to recognise it, the method step by step, and one question to try.

Type 1very common4 practice Q

Malware identification by behaviour

How to spot it:

A short scenario describes what the program does, and its name is asked.

Method
  1. Find the key action: spreads, hides, locks, spies or records.

  2. Check whether a host file is needed.

  3. Match the action to the table.

Why it works:

Every malware type has one signature behaviour.

Try this

A program pretends to be a free game but secretly opens a back door. It is a:

Show solution
  1. It looks useful.

  2. It hides its true purpose.

  3. It does not copy itself, so it is a trojan.

Answer

Trojan horse

Type 2very common3 practice Q

Ransomware scenarios

How to spot it:

Files are locked and a payment is demanded.

Method
  1. Spot the words locked, encrypted or pay.

  2. Name it ransomware.

  3. Recall WannaCry (2017) as the example.

Why it works:

The demand for money is the clear sign.

Try this

A message says your files are encrypted and asks for payment to unlock them. This is:

Show solution
  1. Files are locked.

  2. Money is demanded.

Answer

Ransomware

Type 3common3 practice Q

Spyware, keylogger and adware

How to spot it:

The scenario says information is collected, keys are recorded or ads keep appearing.

Method
  1. Secret collection of information is spyware.

  2. Recording key presses is a keylogger.

  3. Unwanted advertisements are adware.

Why it works:

These three are close relatives, and the action separates them.

Try this

Which malware records every key pressed to steal passwords?

Show solution
  1. It records key presses.

  2. The name says so.

Answer

Keylogger

Type 4common3 practice Q

Botnet and zombies

How to spot it:

Many infected machines are controlled together.

Method
  1. Spot the words army, zombie or remote control.

  2. Name it a botnet.

  3. Recall that botnets often drive DDoS attacks.

Why it works:

A botnet is the tool behind large floods.

Try this

A network of infected computers controlled by one attacker is called a:

Show solution
  1. Many machines are infected.

  2. One attacker controls them.

Answer

Botnet

Type 5very common

Virus vs worm vs trojan

How to spot it:

Two or three malware names are offered, and one matches the description.

Method
  1. Ask if it needs a host file.

  2. Ask if it copies itself.

  3. Virus needs a host. Worm copies alone. Trojan does not copy.

Why it works:

This trio is the most used exam pair.

Try this

Which malware spreads through a network without needing a host file?

Show solution
  1. A virus needs a host.

  2. A trojan does not spread by itself.

  3. A worm spreads alone.

Answer

Worm

07

Shortcuts that save time

⚡ Host test

A virus needs a host file. A worm needs none. A trojan copies nothing.

Example

A program spreads across a network by itself with no host file. What is it?

Show solution
  1. No host file is needed.

  2. It copies itself.

  3. That is a worm.

Answer

Worm

⚡ Money test

If files are locked and money is demanded, it is ransomware. WannaCry in 2017 is the standard example.

08

Mistakes to avoid

Where most students lose marks on this subtopic.

Mistake 01

Saying a worm needs a host file.

A virus needs a host. A worm spreads on its own.

Mistake 02

Saying a trojan copies itself.

A trojan does not copy itself. It hides inside useful-looking software.

Mistake 03

Calling ransomware a kind of spyware.

Ransomware locks files for money. Spyware secretly collects information.

Mistake 04

Thinking a keylogger records the screen.

A keylogger records key presses.

Mistake 05

Thinking one slow computer proves malware.

Slowness is only one sign. Several signs together point to malware.

09

Quick revision

Read this the night before the exam.

  • Malware is malicious software. Virus needs a host, worm needs none, trojan does not copy itself.

  • Ransomware locks files and demands money. WannaCry (2017) is the example.

  • Spyware collects information. Keylogger records key presses. Adware shows ads.

  • Rootkit hides and gives admin rights. Botnet is an army of zombie machines.

  • A logic bomb waits for a trigger date or event.

  • Malware arrives through attachments, pirated software, USB drives and unsafe downloads.

10

Practice: 17 questions

Sets of 10, mixed across the question types above. Every answer has a step-by-step explanation.

Topic test · 10 questions

Suggested time 5 min · wrong answers go to your mistake notebook automatically.