Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports that they received a pop-up warning that their computer is infected with a virus and to call a number for assistance. The pop-up will not close. Which type of malware is this?

⚠ Common exam trap

CompTIA often tests the distinction between scareware and ransomware, where candidates mistakenly choose ransomware because both involve a warning or demand, but ransomware specifically involves encryption or locking of data with a ransom demand, not a fake virus alert prompting a phone call.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scareware

Scareware is a type of malware that displays alarming pop-up messages, often claiming the system is infected with a virus, to trick the user into calling a fake support number or purchasing unnecessary software. The pop-up is designed to be persistent and difficult to close, creating a sense of urgency to coerce the user into action. This matches the scenario exactly, as the user sees a virus warning pop-up that will not close and is instructed to call a number for assistance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ransomware

    Why it's wrong here

    Ransomware's primary goal is financial extortion via encryption of user data; it announces itself with a ransom note demanding payment, often with a countdown, but does not rely on fake infection pop-ups. The pop-up here is a lure to elicit action, not a post-encryption demand. Thus, while malicious, the mechanism and intent differ.

  • ✗

    Rootkit

    Why it's wrong here

    Rootkits operate at kernel or boot level to conceal malicious processes and files, giving attackers persistent undetected access. They avoid drawing attention to themselves, so a conspicuous pop-up claiming an infection would undermine their stealth. Rootkits don't typically generate user-facing alerts; they facilitate other malware silently.

  • ✓

    Scareware

    Why this is correct

    Scareware uses fabricated security alerts and pop-ups to trick users into believing their system is infected, often pressuring them to purchase bogus antivirus software or contact fraudulent tech support. The pop-up warning is the primary attack vector, exploiting urgency and fear to extract money or remote access. This matches the symptom precisely.

  • ✗

    Worm

    Why it's wrong here

    Worms self-replicate and spread across networks by exploiting vulnerabilities, often requiring no user interaction and targeting maximum host compromise. They rarely display persistent pop-ups; their presence is typically observed through network activity or performance degradation. A single warning dialog is a social-engineering tactic, not a worm's characteristic behavior.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.