Identifying Remote Access Trojan Infection Vectors

Malware Types and Attack Vectors
Answer Correct answer: B — A Remote Access Trojan (RAT) infects the system via shared files, allowing remote control without causing performance degradation or failed login attempts.

An administrator is investigating an incident and discovers several users’ computers were infected with malware after viewing files that were shared with them. The administrator discovers no degraded performance in the infected machines and an examination of the log files does not show excessive failed logins. Which of the following attacks is most likely the cause of the malware?

  1. Malicious flash drive
  2. Remote access Trojan Correct Answer
  3. Brute-forced password
  4. Cryptojacking

Community Votes

B
71%
A
29%

71% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of RAT characteristics: stealthy operation, no performance impact, and bypassing standard authentication logs. The common trap is assuming all malware slows down the system or leaves forensic traces like failed logins.

This question tests the ability to distinguish malware infection vectors based on system behavior indicators. It establishes that a Remote Access Trojan (RAT) is the correct answer because it allows remote control without causing performance degradation or failed login attempts.

Many learners choose Malicious Flash Drive (A) because they associate 'no degraded performance' with physical media or assume RATs always consume resources. However, the scenario describes digital file sharing, making physical vectors less likely than network-delivered malware.

Community Discussion (18 comments)

dialecticaljuche1912 👍 8 Selected: B
I dont see how malicious flash drive is part of the comptia syllabus. And RAT is.
AspiringNerd 👍 1 Selected: B
Answer is RAT.
russian 👍 3 Selected: B
Looks more like a RAT
TM78 👍 4 Selected: B
B. A RAT
subaie503 👍 2
RATs are characterized as not causing noticeable changes to the system
[Removed] 👍 4 Selected: B
RAT. I cannot find Comptia docs discussing anything about a RAT ever slowing down a system, and it emphasizes more about how RATs can hide or be legitimate software. Further, a RAT would allow access outside standard logins, so failed auth would not show up in logs. -- Nothing in the question ever implies a flash drive is involved at all, and a malicious flash drive could definitely do some real damage in terms of system performance.
kewokil120 👍 2 Selected: B
Answer is RAT.
salah112 👍 2 Selected: A
A. Malicious flash drive Given that there is no degraded performance on the infected machines and no evidence of excessive failed logins in the log files, a likely scenario is that the malware infection occurred via a malicious flash drive. This form of attack involves spreading malware by infecting external storage devices (such as USB flash drives) and then transferring the malware to computers when those devices are connected.
CaNe2o1 👍 3 Selected: A
Since it's possible RATs can (I know not always but can) slow down a computer, and they mentioned that, I'm going to disregard it and choose A. USB Flash Drive.
7308365 👍 2
B. Remote Access Trojan (RAT) Several users’ computers were infected with malware after viewing files that were shared with them I'm assuming the infected files were shared digitally through an email to multiple users at once, and not physically through a flash drive shared with users one at a time or via multiple infected flash drives given to a group of people at once
Payu1994 👍 2
While it’s true that some Remote Access Trojans (RATs) can slow down a system’s performance, it’s not always the case. The impact on system performance can vary greatly depending on the specific RAT and what it’s programmed to do. Some RATs are designed to be lightweight and stealthy, to avoid detection and maintain long-term access to the infected system. These types of RATs may not noticeably impact system performance. On the other hand, if a RAT is being used to carry out resource-intensive tasks (like cryptocurrency mining or launching DDoS attacks), then you might see a significant slowdown
ThatDetroitGuy 👍 2
I'm going with: B The questions does not specifically mention the file was shared via a flash drive. It could have been shared through a link, sent by email, shared folder, etc.
ganymede 👍 2 Selected: A
A. Malicious flash drive "were infected with malware after viewing files that were shared with them" RAT is not the best answer for that. Malicious flash drive is better.
Susan4041 👍 2 Selected: A
A. Malicious flash drive In the given scenario, the most likely cause of malware infection on users' computers after viewing shared files is a malicious flash drive. Malicious actors may distribute malware using infected USB flash drives or other removable media. Users unknowingly connect the flash drive to their computers, leading to the unintentional installation of malware. The absence of degraded performance and the lack of excessive failed logins suggest that the malware was introduced through a method other than brute-forcing passwords or deploying a remote access Trojan (RAT). Cryptojacking, on the other hand, typically involves unauthorized cryptocurrency mining, and it doesn't align with the symptoms described in the scenario.
Hs1208 👍 3 Selected: A
A. Malicious Flash drive as RATs slow down the system
icebreak 👍 3 Selected: B
B is the correct answer as listed. RAT can be installed without users knowledge by clicking on links.
johnabayot 👍 4 Selected: B
A remote access trojan (RAT) - are typically downloaded together with a seemingly legitimate program, like a game, or are sent to the target as an email attachment. RATs can allow attackers to remotely control the infected machines, access files, and bypass security measures without causing noticeable performance issues or failed logins.
tlolotsis 👍 1
I think answer is A here.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is B, Remote Access Trojan (RAT). A RAT is designed to give attackers remote control over an infected system. Key characteristics include stealthiness; sophisticated RATs are often lightweight and do not cause noticeable system slowdowns or resource exhaustion. Furthermore, since the attacker uses the backdoor provided by the RAT rather than guessing passwords, there would be no excessive failed login attempts in the logs. The infection vector described—viewing shared files—is consistent with social engineering or drive-by downloads associated with RAT distribution.

Why the Other Options Are Wrong

Option A, Malicious Flash Drive, is unlikely because the prompt specifies users were infected after "viewing files that were shared with them," implying a digital delivery method rather than physical media insertion. Option C, Brute-forced password, is incorrect because the logs explicitly show no excessive failed logins, which is the hallmark signature of a brute-force attack. Option D, Cryptojacking, typically causes high CPU usage and significant performance degradation as the machine mines cryptocurrency, contradicting the "no degraded performance" clue.

Community Comment Notes

Community consensus heavily favors B, with many noting that RATs can be stealthy and do not always slow down systems. Some users argue for A based on a misconception that RATs always cause lag, but experts clarify that modern RATs are designed to avoid detection. One commenter noted that RATs allow access outside standard logins, explaining the absence of failed login records. Another pointed out that the digital nature of "shared files" rules out physical flash drives.

Exam Strategy

When analyzing malware scenarios, look for behavioral clues: performance impact, network activity, and log entries. If there is no performance hit and no brute-force signs, consider stealthy remote access tools like RATs rather than resource-intensive attacks like cryptojacking or obvious intrusion attempts like brute force.

Frequently Asked Questions

Why isn't this a brute-force attack?

Brute-force attacks generate excessive failed login attempts in security logs. The scenario states no such failures occurred.

Do all RATs slow down computers?

No. Stealthy RATs are designed to be lightweight to avoid detection and may not cause noticeable performance issues.

Related Analysis

← Back to SY0-601 Study Guide