220-1102 Security Practice Question
A user reports that their Windows 10 workstation is displaying a full-screen message claiming to be from the Federal Bureau of Investigation (FBI), stating that the computer has been locked due to illegal activity and demanding a $500 fine paid via cryptocurrency. The user cannot close the message or access any programs. Which type of malware is this?
⚠ Common exam trap
It's easy for candidates to confuse the FBI-themed scare tactic with a trojan or spyware, but the key differentiator is the system lock and ransom demand, which is a hallmark of ransomware.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
This is ransomware because it restricts access to the system by displaying a full-screen lock message that cannot be closed, and demands a cryptocurrency payment to restore access. Ransomware specifically encrypts files or locks the screen to extort money, which matches the FBI-themed scareware tactic described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ransomware
Why this is correct
Ransomware is a type of malicious software that restricts access to a computer system or files and demands a ransom payment to restore access. In this scenario, the full-screen message claiming a fine and demanding payment is a classic social engineering tactic used by ransomware, often accompanied by encryption of user data or a locked desktop, as seen with law-enforcement-themed ransomware or locker ransomware variants.
- ✗
Spyware
Why it's wrong here
Spyware is designed to covertly monitor user activity, such as capturing keystrokes, browsing habits, or login credentials, and transmit that data to a remote attacker. It does not lock the screen or display extortion messages; its primary goal is stealthy surveillance and data theft, so the presence of a full-screen fine demand rules out spyware as the cause.
- ✗
Rootkit
Why it's wrong here
A rootkit is a collection of malicious tools that provide an attacker with hidden, privileged access to a system while actively concealing its presence from users and security software. Although rootkits can enable other malware or perform deep system modifications, they do not typically present a user-facing full-screen message demanding payment; their value lies in stealth and persistence, not direct user interaction or extortion.
- ✗
Trojan
Why it's wrong here
A trojan is a malicious program that disguises itself as legitimate software to trick users into installing it, and once executed, it can perform a wide range of harmful actions such as deleting files, stealing data, or downloading additional malware. Trojans do not have a single inherent behavior of locking the screen or demanding payment; their effect depends on the payload, and while ransomware is often delivered via a trojan, the final infection presenting the fine message is specifically ransomware.
Go deeper
Related to this question
Learn chapter
Malware Classification: Virus, Worm, Ransomware, Rootkit
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.