Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports that their workstation is displaying pop-up messages claiming to be from a federal law enforcement agency, stating that the computer has been locked due to illegal activity and demanding payment of a fine. The user cannot close the pop-up or access any programs. Which type of malware is this?

⚠ Common exam trap

The 220-1102 exam often tests the distinction between scareware and ransomware by describing a pop-up that 'locks the computer' but does not mention file encryption, leading candidates to incorrectly choose ransomware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scareware

Scareware is designed to frighten the user into taking action, often by displaying fake law enforcement warnings that claim the system is locked due to illegal activity. Unlike ransomware, which encrypts files and demands payment for decryption, scareware typically uses a full-screen browser or system pop-up that can be bypassed by terminating the browser process or using Task Manager. The inability to close the pop-up or access programs is a classic scareware tactic, not true file encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ransomware

    Why it's wrong here

    Ransomware is a type of malware that encrypts files or entire disks, rendering data inaccessible until a ransom is paid, typically in cryptocurrency, in exchange for a decryption key. The scenario describes only a pop-up lock screen with a fake law enforcement warning, not actual file encryption or data loss. While the coercion to pay is similar, the absence of encryption or a cryptographic lock makes ransomware an inaccurate classification for this specific symptom.

  • ✓

    Scareware

    Why this is correct

    Scareware is a social-engineering attack that uses intimidating pop-ups, such as fake law enforcement or security alerts, to trick users into paying for unnecessary 'services' or revealing sensitive information. In this case, the pop-up impersonates authorities and locks the workstation screen to create urgency and fear, coercing the user into paying a fine. This matches the definition of scareware precisely: it relies on psychological pressure rather than actual system compromise, and the 'lock' is merely a full-screen overlay that can often be dismissed by force-quitting the browser or process.

  • ✗

    Adware

    Why it's wrong here

    Adware is software that automatically displays or downloads advertisements, often in the form of banners or pop-ups, to generate revenue for its creator. Unlike the scenario, adware typically does not impersonate law enforcement, does not lock the entire screen, and does not demand payment to resolve a fictitious legal issue. While adware can be annoying and may use pop-ups, it lacks the specific intimidation tactic of a fake police warning that defines this attack as scareware.

  • ✗

    Trojan

    Why it's wrong here

    A Trojan is a broad class of malicious software that disguises itself as a legitimate program to trick users into installing it, after which it may perform various harmful actions. The label 'Trojan' describes the delivery mechanism or general behavior, not the specific pop-up presentation described here. Since the symptom is clearly a fake law enforcement lock screen with a payment demand, 'Trojan' is too generic; the precise category for this social-engineering tactic is scareware.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.