Malware

Malware is any software written to damage, disrupt, or gain unauthorized access to systems and data. The label covers a wide family, including viruses that attach to legitimate programs, worms that self replicate across networks, trojans that hide inside something that looks useful, ransomware that encrypts files for extortion, spyware that quietly surveils, and rootkits that conceal an attacker’s presence on a machine.

Modern samples rarely fit one neat box. They blend techniques, encrypt their own code to slip past scanners, and increasingly run fileless, living only in memory where traditional antivirus struggles to see them. That evolution is why no single product stops malware. Effective defense stacks layers, including prompt patching, email filtering, endpoint detection and response, network monitoring, and user awareness, so that when one control misses, another still has a chance to catch the infection before it spreads.

How is malware tested on the CISSP exam?

Malware appears mainly in Domain 7: Security Operations, which carries 13 percent of the exam, for detection and response, and it also touches software security for prevention. Know the categories, the common infection vectors, and the matching countermeasures.

CISA tracks active threats at StopRansomware.gov.