Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports that their Windows 10 workstation has been displaying a warning message stating that all files have been encrypted by the IT department due to a security breach. The message instructs the user to call a premium-rate phone number to receive the decryption key. The user reports that they cannot open any documents, and file extensions have been changed to .encrypted. Which type of malware is this?

⚠ Common exam trap

Many exam-takers confuse scareware with ransomware because both display alarming messages, but scareware does not actually encrypt files or change extensions—it only simulates threats to sell fake software.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ransomware

B is correct because ransomware encrypts files and demands payment for decryption. The warning message, inability to open documents, and changed file extensions (.encrypted) are classic indicators of ransomware, which uses symmetric or asymmetric encryption (e.g., AES-256, RSA) to lock files and extort the victim.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Scareware

    Why it's wrong here

    Scareware is a category of malicious software that bombards a user with alarming pop-ups and fake system warnings, claiming critical infections or errors have been detected. Its goal is to frighten the victim into purchasing a bogus 'full version' of the software to remove the nonexistent threat. Unlike the scenario described, scareware does not encrypt or lock files; it relies purely on social engineering and psychological pressure rather than data hostage-taking.

  • ✓

    Ransomware

    Why this is correct

    Ransomware is a form of malware that specifically employs cryptographic encryption to lock a victim's files, rendering them inaccessible. The attacker then demands a monetary payment, typically in cryptocurrency, in exchange for the decryption key. This matches the described situation exactly: a warning appears (often as a ransom note) and files are encrypted, coercing the user to pay for restored access.

  • ✗

    Adware

    Why it's wrong here

    Adware is software that automatically displays unwanted advertisements, often in pop-up windows, browser toolbars, or embedded in other applications. Its primary revenue model is generating ad views or clicks for its developers, usually without the user's meaningful consent. While intrusive and sometimes bundled with other malware, adware does not encrypt files or demand ransom payments; it focuses entirely on ad delivery and tracking user behavior.

  • ✗

    Worm

    Why it's wrong here

    A worm is a standalone malicious program that self-replicates and spreads across networks without requiring human interaction or a host file to attach to. It exploits vulnerabilities or weak credentials to move from machine to machine, often consuming bandwidth or dropping payloads like other malware. While some worms carry ransomware components, the act of replication itself does not involve file encryption for ransom, so it does not match a direct file-encrypting warning scenario.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.