220-1102 Security Practice Question
A helpdesk technician receives a call from a user who reports that their antivirus software is disabled and cannot be re-enabled. Additionally, the user's files have been renamed with a '.encrypted' extension. Which type of malware is most likely responsible?
⚠ Common exam trap
Test-takers frequently confuse ransomware with a Trojan because both can be delivered via social engineering, but the specific symptom of file encryption with a '.encrypted' extension is unique to ransomware, not a general Trojan behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
C is correct because ransomware is a type of malware that encrypts the user's files, appending a '.encrypted' extension, and often disables security software like antivirus to prevent removal or remediation. The symptoms of files being renamed with '.encrypted' and the inability to re-enable antivirus are classic indicators of a ransomware attack, which demands payment for the decryption key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trojan
Why it's wrong here
A Trojan is malware that disguises itself as a legitimate application or file to trick a user into executing it. While some Trojans can carry encryption modules or download ransomware as a secondary payload, their primary behavior is facilitating unauthorized remote access, data theft, or the installation of other malware. They are not designed to uniformly disable antivirus tools and then encrypt the entire user data set with a ransom demand; that direct, focused behavior is the hallmark of dedicated ransomware.
- ✗
Worm
Why it's wrong here
A worm is a self-replicating standalone program that spreads autonomously across network shares, email clients, or removable media without user interaction. Its core objective is propagation, usually consuming network bandwidth or delivering secondary payloads, but it does not inherently target user files with encryption or disable antivirus software as part of a typical infection lifecycle. Although a worm might drop ransomware as a payload, the reported combination of security tools being turned off and files being encrypted is not the worm's own behavior but rather that of the subsequent ransomware component.
- ✓
Ransomware
Why this is correct
Ransomware is specifically constructed to disable or evade security software, encrypt the victim's files or even whole volumes, and then display an extortion note demanding payment for the decryption key. Modern ransomware often terminates antivirus processes and clears shadow copies to make file recovery impossible without paying, which matches the user's report exactly. The dual symptom set of disabled security tools and encrypted files is the classic, high-confidence signature of a ransomware attack, distinguishing it clearly from Trojans, worms, and rootkits.
- ✗
Rootkit
Why it's wrong here
A rootkit is designed to maintain persistent, privileged access to a system while actively hiding its presence, files, processes, and network connections from administrators and security tools. It typically achieves stealth by hooking system calls, patching the kernel, or manipulating the boot process, and although it might disable security software to protect itself, it does not run file-encryption routines aimed at extortion. On the remote chance a rootkit carries encryption code, that would still be the action of a component, not the rootkit's defining functionality; systematic user-data encryption with a ransom note is outside the normal scope of rootkit operations.
Go deeper
Related to this question
Learn chapter
Malware Classification: Virus, Worm, Ransomware, Rootkit
Key term
Antivirus
Antivirus is software that detects, prevents, and removes malicious software (malware) from a computer or network.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.