Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports that their Windows 10 workstation is displaying a full-screen message claiming to be from the Federal Bureau of Investigation (FBI), stating that the computer has been locked due to illegal activity and demanding a $500 fine paid via cryptocurrency. The user cannot close the message or access any programs. Which type of malware is this?

⚠ Common exam trap

It's easy for candidates to confuse the FBI-themed scare tactic with a trojan or spyware, but the key differentiator is the system lock and ransom demand, which is a hallmark of ransomware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ransomware

This is ransomware because it restricts access to the system by displaying a full-screen lock message that cannot be closed, and demands a cryptocurrency payment to restore access. Ransomware specifically encrypts files or locks the screen to extort money, which matches the FBI-themed scareware tactic described.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ransomware

    Why this is correct

    Ransomware is a type of malicious software that restricts access to a computer system or files and demands a ransom payment to restore access. In this scenario, the full-screen message claiming a fine and demanding payment is a classic social engineering tactic used by ransomware, often accompanied by encryption of user data or a locked desktop, as seen with law-enforcement-themed ransomware or locker ransomware variants.

  • ✗

    Spyware

    Why it's wrong here

    Spyware is designed to covertly monitor user activity, such as capturing keystrokes, browsing habits, or login credentials, and transmit that data to a remote attacker. It does not lock the screen or display extortion messages; its primary goal is stealthy surveillance and data theft, so the presence of a full-screen fine demand rules out spyware as the cause.

  • ✗

    Rootkit

    Why it's wrong here

    A rootkit is a collection of malicious tools that provide an attacker with hidden, privileged access to a system while actively concealing its presence from users and security software. Although rootkits can enable other malware or perform deep system modifications, they do not typically present a user-facing full-screen message demanding payment; their value lies in stealth and persistence, not direct user interaction or extortion.

  • ✗

    Trojan

    Why it's wrong here

    A trojan is a malicious program that disguises itself as legitimate software to trick users into installing it, and once executed, it can perform a wide range of harmful actions such as deleting files, stealing data, or downloading additional malware. Trojans do not have a single inherent behavior of locking the screen or demanding payment; their effect depends on the payload, and while ransomware is often delivered via a trojan, the final infection presenting the fine message is specifically ransomware.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.