Courseiva
easyMultiple ChoiceObjective-mapped

220-1202 Practice Question: During a routine security audit, a technician…

During a routine security audit, a technician finds that a user's computer has an unknown program running that is sending keystrokes and screenshots to a remote server. The user did not install this program. Which type of malware is this?

⚠ Common exam trap

Test-takers frequently confuse a keylogger with a rootkit because both can operate stealthily, but the rootkit's primary function is hiding itself and other malware, not capturing keystrokes or screenshots.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Keylogger

The described behavior—capturing keystrokes and screenshots and sending them to a remote server—is the defining characteristic of a keylogger. This type of malware specifically records user input and screen activity to steal sensitive data like passwords and personal information, and it often runs without the user's knowledge or consent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Rootkit

    Why it's wrong here

    A rootkit is a collection of malicious software designed to enable access to a computer or an area of its software that is not otherwise allowed, while simultaneously hiding its existence from other software. While a rootkit provides persistent, privileged access and can conceal other malware, its primary function is not to directly capture keystrokes or screenshots. Instead, it creates a stealthy environment for other malicious activities, which could include a keylogger, but it isn't the keylogger itself.

  • Worm

    Why it's wrong here

    A worm is a standalone malware computer program that replicates itself in order to spread to other computers, typically across a network. Unlike viruses, worms do not need to attach to an existing program to spread. Their primary objective is self-propagation and consumption of network bandwidth or system resources, not the covert capture of user input like keystrokes or visual data like screenshots.

  • Keylogger

    Why this is correct

    A keylogger, also known as a keystroke logger, is a type of surveillance technology used to monitor and record each keystroke typed on a specific computer's keyboard. Many advanced keyloggers also incorporate additional data capture features, such as periodically taking screenshots, recording clipboard contents, or monitoring web browser activity. This direct and covert capture of both keystrokes and visual information precisely matches the described findings of the security audit.

  • Ransomware

    Why it's wrong here

    Ransomware is a type of malicious software that threatens to publish the victim's data or perpetually block access to it unless a ransom is paid. It typically encrypts files on the victim's system, making them inaccessible, and then displays a demand for payment to decrypt them. Its primary objective is financial extortion through data denial, not the surreptitious logging of user input or visual information.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.