easyMultiple ChoiceObjective-mapped
220-1202 Practice Question: That their workstation is running slowly and they…
A user reports that their workstation is running slowly and they see a pop-up claiming their files are encrypted and a ransom must be paid. They cannot open any documents. What type of malware is most likely responsible?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
Ransomware encrypts files and demands payment for decryption. This scenario describes classic ransomware behavior, where the user is locked out of their data and a ransom note is displayed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spyware
Why it's wrong here
Spyware is a type of malicious software designed to covertly monitor user activity and collect personal information, such as browsing habits, keystrokes, or sensitive data, without explicit consent. While it can consume system resources and lead to performance degradation, its primary objective is data exfiltration and surveillance, not file encryption or displaying ransom demands. Therefore, it does not fit the scenario of a ransom demand.
- ✓
Ransomware
Why this is correct
Ransomware is a type of malicious software that encrypts a victim's files, rendering them inaccessible, and then demands a ransom payment, typically in cryptocurrency, for the decryption key. The initial encryption process can significantly slow down a workstation, and the subsequent display of a ransom note directly matches the described symptoms of a system running slowly and demanding payment. This attack directly targets data availability and extorts payment.
- ✗
Trojan horse
Why it's wrong here
A Trojan horse is malware that masquerades as legitimate software to trick users into executing it, thereby gaining unauthorized access to a system. Its primary function is to create backdoors, steal data, or install other malicious payloads, but it does not inherently encrypt files or demand ransom as its core functionality. While a Trojan could be a delivery mechanism for ransomware, it is not the ransomware itself.
- ✗
Rootkit
Why it's wrong here
A rootkit is a stealthy type of malicious software designed to hide its presence and the presence of other malware on a computer system, often by modifying core operating system processes or kernel functions. It provides persistent, unauthorized access and allows attackers to maintain control while evading detection by security software. However, a rootkit's main purpose is concealment and control, not the encryption of user files and the display of ransom demands.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1202
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A user reports that their workstation is running slowly and they see frequent pop-up ads even when no browser is open. They also notice a new toolbar in their system tray that they did not install. What is the most likely security issue?
easy- A.A rootkit has hidden itself in the kernel.
- ✓ B.The system has adware installed.
- C.A ransomware encryption process has started.
- D.The user's account has been phished and credentials stolen.
Why B: Adware is a type of malware that displays unwanted advertisements, often in the form of pop-ups or browser redirects, and may install toolbars or other unwanted software without the user's consent. The presence of a new toolbar in the system tray and frequent pop-ups even when no browser is open are classic indicators of adware infection, as adware often runs background processes to generate revenue through ad impressions.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.