ALL PASS, NO FAIL!

CEH v13 Module 7: Malware Threats — Free Practice Questions with Explanations

Last updated September 2026 · 10 questions · Module 7 of 20

Malware types and lifecycle: viruses, worms, trojans, ransomware, rootkits, APT toolkits, and static vs. dynamic analysis. Exam focus: match each malware family — virus, worm, trojan, rootkit, RAT, fileless — to its behavior and detection signature, then practice identifying the family from a plain-English incident description.

⚠️ Important Disclaimer: These practice questions are original study material created by CEHStudy for educational purposes. They are NOT EC-Council exam questions and do NOT replicate the actual exam. CEHStudy is not affiliated with or endorsed by EC-Council.

Question 1: The key difference between a computer virus and a worm is:

Answer: B — Viruses attach to files/programs and need a user to execute them; worms are standalone and propagate autonomously over networks.

Question 2: Metamorphic malware differs from polymorphic malware because it:

Answer: D — Polymorphic strains mutate signatures via a mutation engine; metamorphic engines rebuild the whole program while preserving function — harder to detect.

Question 3: Fileless malware is difficult to detect because it:

Answer: D — Living-off-the-land (PowerShell -encodedcommand, WMI event subscriptions) leaves no file for signature-based AV to find.

Question 4: Malicious code that stays dormant until a specific condition (date, event, password) is met is called a:

Answer: D — Logic bombs are planted to detonate when triggered — a classic insider/disgruntled-employee payload.

Question 5: An Advanced Persistent Threat (APT) is characterized by:

Answer: D — APTs (e.g., APT28/29, Lazarus) use custom malware and zero-days to stay hidden inside high-value targets for extended periods.

Question 6: A botnet is:

Answer: D — C&C (hub-and-spoke, P2P, or DNS-based) commands the bots to launch DDoS, spam, or mining (e.g., Mirai, Emotet).

Question 7: 'Double extortion' ransomware:

Answer: A — Modern families (LockBit, BlackCat) exfiltrate first — so even after decryption or backups, attackers can publish stolen data.

Question 8: Cryptomining malware (cryptojacking) is commonly detected by signs such as:

Answer: B — Mining Proof-of-Work puzzles pins compute resources — elevated CPU, fan noise, and billing spikes are the telltale signs.

Question 9: Executing malware in a sandbox to observe its file, network, and registry behavior is known as:

Answer: A — Dynamic analysis (Cuckoo, Joe Sandbox) reveals runtime behavior; static analysis inspects code without executing it.

Question 10: Stuxnet is historically significant because it was:

Answer: C — Discovered in 2010, Stuxnet used multiple zero-days to alter Iran's nuclear centrifuge operations — proof that code can break physical systems.

Related Glossary Terms

Continue Your CEH v13 Prep

Frequently Asked Questions

How many CEH v13 Malware Threats practice questions are on this page?

This page includes 10 original multiple-choice practice questions for CEH v13 Module 7 (Malware Threats). Each question includes a detailed explanation of the correct answer and why the other options are wrong. The full CEHStudy question bank covers all 20 modules with 200+ questions — see the practice hub at https://cehstudy.com/ceh-practice-questions/ for every module.

What does CEH v13 Module 7 (Malware Threats) cover?

Malware types and lifecycle: viruses, worms, trojans, ransomware, rootkits, APT toolkits, and static vs. dynamic analysis. These are the same topics tested under this module on the EC-Council 312-50 exam. Pair this quiz with our free Module 7 flashcards at https://cehstudy.com/ceh-v13/module-07/ to close any gaps.

Are these real CEH exam questions?

No. Every question on CEHStudy is original study material written for exam preparation. They match the style, difficulty, and domain coverage of the actual CEH v13 exam but are not leaked or reproduced EC-Council questions.

How should I use this Malware Threats quiz for exam prep?

Answer all 10 questions without peeking at explanations, then click "Show My Score". Review every explanation — especially the ones you missed — and re-test those topics with our free CEH flashcards. Aim for 80% or higher on module quizzes before scheduling the exam.

Where do I find CEH Malware Threats flashcards?

Our free flashcard app covers all 20 CEH v13 modules including Module 7 (Malware Threats). Visit the CEH flashcards page at https://cehstudy.com/ or the Module 7 page at https://cehstudy.com/ceh-v13/module-07/. No account or sign-up required.