ITPEC IP October 2025 Question 36

Source exam: ITPEC IP October 2025Topic: Security

ITPEC IP October 2025 — Question 36 of 100

The threats are XSS, bot, and Trojan horse in that order — each description contains the defining behavior of one term.

  • (i) An injected script executing in a visitor's browser is cross-site scripting (XSS)
  • (ii) Malware controlled over a network as part of a coordinated attack is a bot
  • (iii) Malware disguised as useful software is a Trojan horse

Answer (b)

Why not others:
- (a) reverses the bot and Trojan horse in (ii) and (iii)

- (c) incorrectly calls the browser script a targeted attack and the controlled malware XSS

- (d) assigns none of the three definitions to its proper term

Key rule: XSS runs injected browser script; a bot obeys remote commands; a Trojan relies on a useful-looking disguise.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.