ITPEC IP October 2025 Question 36
ITPEC IP October 2025 — Question 36 of 100
The threats are XSS, bot, and Trojan horse in that order — each description contains the defining behavior of one term.
- •(i) An injected script executing in a visitor's browser is cross-site scripting (XSS)
- •(ii) Malware controlled over a network as part of a coordinated attack is a bot
- •(iii) Malware disguised as useful software is a Trojan horse
Answer (b)
Why not others:
- (a) reverses the bot and Trojan horse in (ii) and (iii)
- (c) incorrectly calls the browser script a targeted attack and the controlled malware XSS
- (d) assigns none of the three definitions to its proper term
Key rule: XSS runs injected browser script; a bot obeys remote commands; a Trojan relies on a useful-looking disguise.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.