Courseiva
easyMultiple ChoiceObjective-mapped

220-1102 Practice Question: During a routine security audit, a technician…

During a routine security audit, a technician discovers that a user's workstation has a program that records keystrokes and periodically sends the data to an external server. The user denies installing any software recently. Which type of malware is this?

⚠ Common exam trap

Many candidates confuse the delivery method (e.g., a Trojan horse) with the malware's primary function, but the question focuses on the observed behavior (keystroke recording and data exfiltration), which directly identifies it as a keylogger, not the method of installation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Keylogger

The program described records keystrokes and exfiltrates them to an external server, which is the defining behavior of a keylogger. This type of malware captures user input, such as usernames and passwords, and sends the data to an attacker. The user's denial of installing software suggests the keylogger may have been delivered stealthily, often via a Trojan horse or drive-by download, but the core functionality is keylogging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Trojan horse

    Why it's wrong here

    A Trojan horse is a type of malware that masquerades as legitimate software or a benign file to trick users into executing it. Once activated, it can perform various malicious actions, such as creating backdoors for remote access, deleting data, or launching other malware. While some Trojans might deliver a keylogger payload, the Trojan itself is the delivery mechanism, not the keylogger functionality that records keystrokes. Therefore, it doesn't directly fit the description of recording keystrokes and sending them to a server.

  • Worm

    Why it's wrong here

    A worm is a standalone malicious program that replicates itself to spread to other computers, typically across a network, without needing to attach to an existing program or user interaction for propagation. Its primary function is self-replication and consumption of network bandwidth or system resources, often leading to denial-of-service conditions. While a worm might carry a payload, its inherent design is not focused on recording keystrokes or exfiltrating specific user input data to a remote server, making it an incorrect fit for the described scenario.

  • Keylogger

    Why this is correct

    A keylogger is a type of surveillance software or hardware designed to record every keystroke made on a target computer's keyboard. These recorded inputs, which can include sensitive information like usernames, passwords, and credit card numbers, are then typically stored locally or covertly transmitted to a remote attacker's server. This direct and specific functionality of capturing and exfiltrating keystroke data precisely matches the scenario of a security audit discovering a mechanism for recording keystrokes and sending them to a server.

  • Ransomware

    Why it's wrong here

    Ransomware is a malicious software that encrypts a victim's files or locks their computer system, then demands a ransom payment, usually in cryptocurrency, in exchange for decryption keys or system access. Its primary objective is financial extortion through data unavailability, not covert data exfiltration like recording keystrokes. While it can cause significant disruption and data loss, its operational mechanism does not involve monitoring or transmitting user input, making it an unsuitable answer for the described security discovery.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.