220-1102 Security Practice Question
A user reports that their Windows 10 workstation has been displaying a warning message stating that all files have been encrypted by the IT department due to a security breach. The message instructs the user to call a premium-rate phone number to receive the decryption key. The user reports that they cannot open any documents, and file extensions have been changed to .encrypted. Which type of malware is this?
⚠ Common exam trap
Many exam-takers confuse scareware with ransomware because both display alarming messages, but scareware does not actually encrypt files or change extensions—it only simulates threats to sell fake software.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
B is correct because ransomware encrypts files and demands payment for decryption. The warning message, inability to open documents, and changed file extensions (.encrypted) are classic indicators of ransomware, which uses symmetric or asymmetric encryption (e.g., AES-256, RSA) to lock files and extort the victim.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Scareware
Why it's wrong here
Scareware is a category of malicious software that bombards a user with alarming pop-ups and fake system warnings, claiming critical infections or errors have been detected. Its goal is to frighten the victim into purchasing a bogus 'full version' of the software to remove the nonexistent threat. Unlike the scenario described, scareware does not encrypt or lock files; it relies purely on social engineering and psychological pressure rather than data hostage-taking.
- ✓
Ransomware
Why this is correct
Ransomware is a form of malware that specifically employs cryptographic encryption to lock a victim's files, rendering them inaccessible. The attacker then demands a monetary payment, typically in cryptocurrency, in exchange for the decryption key. This matches the described situation exactly: a warning appears (often as a ransom note) and files are encrypted, coercing the user to pay for restored access.
- ✗
Adware
Why it's wrong here
Adware is software that automatically displays unwanted advertisements, often in pop-up windows, browser toolbars, or embedded in other applications. Its primary revenue model is generating ad views or clicks for its developers, usually without the user's meaningful consent. While intrusive and sometimes bundled with other malware, adware does not encrypt files or demand ransom payments; it focuses entirely on ad delivery and tracking user behavior.
- ✗
Worm
Why it's wrong here
A worm is a standalone malicious program that self-replicates and spreads across networks without requiring human interaction or a host file to attach to. It exploits vulnerabilities or weak credentials to move from machine to machine, often consuming bandwidth or dropping payloads like other malware. While some worms carry ransomware components, the act of replication itself does not involve file encryption for ransom, so it does not match a direct file-encrypting warning scenario.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Encryption Concepts for A+
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.