ExamShortcut

Cyber Security

🔒 Log in to track
high importance⚡ 9 shortcuts4 subtopics
All subtopics·Subtopic 1 of 4
⏱ 4 min read🧩 4 question types🎯 17 practice Q
The idea in one minute

Malware = malicious software. The family table:

MalwareBehaviourSpread
VirusAttaches itself to a host file/program; corrupts dataOnly when the infected file is run/shared
WormSelf-replicates across networks without any host file or user actionAutomatically over the network
Trojan (horse)Disguises as useful software; opens backdoors, steals dataDoes NOT self-replicate; user installs it
RansomwareEncrypts the victim's files and demands ransom (WannaCry, 2017)Mail attachments, exploits
SpywareSecretly collects user activity/dataBundled installs, drive-by
KeyloggerRecords every keystroke (passwords, OTPs)Often part of spyware/trojans
AdwareForces unwanted advertisementsFreeware bundles
RootkitHides deep in the OS with admin rights, concealing other malwareExploits
BotnetNetwork of infected 'zombie' machines under a attacker's control (used for DDoS/spam)Worm/trojan infection
Logic bombDormant code that fires on a trigger (date, event)Planted insider/trojan

WannaCry (2017) - global ransomware outbreak hitting unpatched Windows via the EternalBlue exploit - is the stock example question.

01

Malware — hostile software

Malware (MALicious softWARE) is any program written to harm, steal or spy. Exams test one skill: matching the malware's behaviour to its name.

MalwareSignature behaviour
Virusattaches itself to a file/program and spreads when that file is run — needs a host
Wormself-replicates on its own across networks — needs no host file
Trojan horsehides inside useful-looking software (free game, "update"); does not replicate
Ransomwarelocks/encrypts your files and demands money (e.g. WannaCry, 2017)
Spywaresecretly collects your information and sends it out
Keyloggerrecords every keystroke — passwords typed are captured (a spyware cousin)
Adwarefloods the screen with unwanted advertisements
Botnetmany infected "zombie" machines remotely controlled as one army (for spam/DDoS)
Rootkitburies itself deep in the system, hides its presence, grants attacker admin rights
02

The three distinctions exams plant

  1. Virus vs Worm: a virus rides on a host file and waits for you to run it; a worm needs no host — it crawls through the network by itself.
  2. Trojan vs Virus: a trojan never replicates — it waits, disguised as legitimate software, and opens the door from inside (backdoor).
  3. Ransomware vs Spyware: ransomware takes your files hostage for money; spyware takes copies quietly and leaves everything in place.
03

How malware arrives

Infected email attachments and links, pirated software, infected USB drives, drive-by downloads from unsafe sites, and fake "your PC is infected" pop-ups. Once inside, malware may slow the machine, corrupt or delete files, steal data, or enlist the machine into a botnet without the owner noticing anything beyond sluggishness.

04

Symptoms of an infected machine

Unexplained slowness, files renamed or missing, programs opening on their own, browser home page changed, sudden pop-ups, the fan and disk working when you do nothing. None of these proves malware alone — but together they are the exam's favourite scenario line.

05

Question types you will see

Each type: how to recognise it, the method step by step, and one question to try.

Type 1very common4 practice Q

Malware identification by behaviour

How to spot it:

A behaviour is described ('self-replicates without a host', 'disguises as useful software', 'encrypts files for ransom') and the malware is asked.

Method
  1. Needs a host file = Virus; self-replicates alone over the network = Worm.

  2. Disguised as useful software, does not replicate = Trojan horse.

  3. Locks files and demands money = Ransomware; watches silently = Spyware/Keylogger.

Try this

A program that enters a computer disguised as a free game and does not replicate is a:

Show solution

Trojan horse — the disguise is its signature; replication belongs to virus/worm.

Type 2common3 practice Q

Ransomware scenarios

How to spot it:

'Files are locked and money is demanded', 'WannaCry' or any hostage-style scenario.

Method
  1. Encrypt-and-demand-money = Ransomware — the fastest identification in the topic.

  2. Defence = offline backups; paying the ransom is never advised.

  3. WannaCry (2017) is the named example exams use.

Try this

A hospital finds all its patient records encrypted with a demand for money to unlock them. This is:

Show solution

Ransomware — data taken hostage; restored from backups, not by paying.

Type 3common3 practice Q

Spyware, keylogger and adware

How to spot it:

'Records every keystroke', 'secretly collects browsing data', 'shows endless advertisements' — the quiet watchers.

Method
  1. Records keystrokes = Keylogger (passwords captured as you type).

  2. Secretly gathers and sends your information = Spyware.

  3. Throws unwanted ads = Adware. All three spy or annoy — none of them locks files.

Try this

Ravi suspects his typed passwords are being captured as he types them. Which malware fits?

Show solution

Keylogger — it records every keystroke, so even a strong password leaks.

Type 4occasional3 practice Q

Botnet and zombies

How to spot it:

'A network of infected computers controlled by an attacker', 'zombie machines used for spam/DDoS'.

Method
  1. Botnet = many infected 'zombie' machines remotely commanded as one — owners usually unaware.

  2. Botnets are the muscle behind DDoS floods and mass spam.

  3. The controller is the 'bot herder'; your slow machine may be someone's soldier.

Try this

Thousands of infected home computers are ordered together to flood one server. The infected network is a:

Show solution

Botnet — the army of zombies that powers DDoS attacks.

06

Shortcuts that save time

⚡ V-W-T triangle

Virus needs a Vehicle (host file); Worm Wanders alone; Trojan Tricks you into installing. Replication + host = virus; replication without host = worm; disguise without replication = trojan.

Example

Which malware self-replicates without needing a host file?

Show solution

Worm.

⚡ Ransom = Ransomware

Encrypts your files, demands money -> ransomware (WannaCry). 'Keystrokes recorded' -> keylogger. 'Hides with admin rights' -> rootkit. 'Zombie army' -> botnet.

Example

WannaCry (2017) was an example of?

Show solution

Ransomware.

07

Mistakes to avoid

Where most students lose marks on this subtopic.

Mistake 01

Saying a trojan self-replicates - only viruses and worms replicate; a trojan relies on disguise.

Mistake 02

Saying a worm needs a host file - the worm is host-free by definition.

Mistake 03

Calling ransomware a 'data thief' - its business model is encryption + extortion.

08

Quick revision

Read this the night before the exam.

  • Virus needs a host; Worm needs none; Trojan replicates not.

  • Ransomware = lock and demand money (WannaCry 2017); Spyware spies; Keylogger records keystrokes.

  • Botnet = army of zombie machines; Rootkit = hidden admin-level intruder.

  • Malware spreads by attachments, pirated software, unsafe downloads.

09

Practice: 17 questions

Sets of 10, mixed across the question types above. Every answer has a step-by-step explanation.

Topic test · 10 questions

Suggested time 5 min · wrong answers go to your mistake notebook automatically.