Identifying Remote Access Trojan Infection Vectors
An administrator is investigating an incident and discovers several users’ computers were infected with malware after viewing files that were shared with them. The administrator discovers no degraded performance in the infected machines and an examination of the log files does not show excessive failed logins. Which of the following attacks is most likely the cause of the malware?
Community Votes
71% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests knowledge of RAT characteristics: stealthy operation, no performance impact, and bypassing standard authentication logs. The common trap is assuming all malware slows down the system or leaves forensic traces like failed logins.
This question tests the ability to distinguish malware infection vectors based on system behavior indicators. It establishes that a Remote Access Trojan (RAT) is the correct answer because it allows remote control without causing performance degradation or failed login attempts.
Many learners choose Malicious Flash Drive (A) because they associate 'no degraded performance' with physical media or assume RATs always consume resources. However, the scenario describes digital file sharing, making physical vectors less likely than network-delivered malware.
Community Discussion (18 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is B, Remote Access Trojan (RAT). A RAT is designed to give attackers remote control over an infected system. Key characteristics include stealthiness; sophisticated RATs are often lightweight and do not cause noticeable system slowdowns or resource exhaustion. Furthermore, since the attacker uses the backdoor provided by the RAT rather than guessing passwords, there would be no excessive failed login attempts in the logs. The infection vector described—viewing shared files—is consistent with social engineering or drive-by downloads associated with RAT distribution.Why the Other Options Are Wrong
Option A, Malicious Flash Drive, is unlikely because the prompt specifies users were infected after "viewing files that were shared with them," implying a digital delivery method rather than physical media insertion. Option C, Brute-forced password, is incorrect because the logs explicitly show no excessive failed logins, which is the hallmark signature of a brute-force attack. Option D, Cryptojacking, typically causes high CPU usage and significant performance degradation as the machine mines cryptocurrency, contradicting the "no degraded performance" clue.Community Comment Notes
Community consensus heavily favors B, with many noting that RATs can be stealthy and do not always slow down systems. Some users argue for A based on a misconception that RATs always cause lag, but experts clarify that modern RATs are designed to avoid detection. One commenter noted that RATs allow access outside standard logins, explaining the absence of failed login records. Another pointed out that the digital nature of "shared files" rules out physical flash drives.Exam Strategy
When analyzing malware scenarios, look for behavioral clues: performance impact, network activity, and log entries. If there is no performance hit and no brute-force signs, consider stealthy remote access tools like RATs rather than resource-intensive attacks like cryptojacking or obvious intrusion attempts like brute force.
Frequently Asked Questions
Why isn't this a brute-force attack?
Brute-force attacks generate excessive failed login attempts in security logs. The scenario states no such failures occurred.
Do all RATs slow down computers?
No. Stealthy RATs are designed to be lightweight to avoid detection and may not cause noticeable performance issues.