GCIH · Question #65
Which of the following can be used as a Trojan vector to infect an information system? Each correct answer represents a complete solution. Choose all that apply.
The correct answer is A. NetBIOS remote installation B. Any fake executable C. Spywares and adware D. ActiveX controls, VBScript, and Java scripts. Trojans can be delivered through many vectors including remote installation, fake executables, bundled spyware/adware, and client-side scripting technologies. All four options represent valid Trojan infection vectors.
Question
Which of the following can be used as a Trojan vector to infect an information system? Each correct answer represents a complete solution. Choose all that apply.
Options
- ANetBIOS remote installation
- BAny fake executable
- CSpywares and adware
- DActiveX controls, VBScript, and Java scripts
How the community answered
(28 responses)- A100% (28)
Why each option
Trojans can be delivered through many vectors including remote installation, fake executables, bundled spyware/adware, and client-side scripting technologies. All four options represent valid Trojan infection vectors.
NetBIOS remote installation allows an attacker to push and execute malicious software on remote systems over a network share, making it a valid Trojan delivery mechanism.
Fake executables are the classic Trojan vector - a malicious payload disguised as a legitimate program that a user willingly runs.
Spyware and adware are frequently bundled with or used to download Trojan payloads, serving as secondary infection vehicles once they are installed.
ActiveX controls, VBScript, and JavaScript executed in a browser context can download and run Trojan payloads without explicit user consent, exploiting browser trust models.
Concept tested: Trojan horse malware delivery vectors
Source: https://www.cisa.gov/uscert/ncas/tips/ST04-010
Topics
Community Discussion
No community discussion yet for this question.