220-1102 Security Practice Question
A user reports that they received a pop-up warning that their computer is infected with a virus and to call a number for assistance. The pop-up will not close. Which type of malware is this?
⚠ Common exam trap
CompTIA often tests the distinction between scareware and ransomware, where candidates mistakenly choose ransomware because both involve a warning or demand, but ransomware specifically involves encryption or locking of data with a ransom demand, not a fake virus alert prompting a phone call.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scareware
Scareware is a type of malware that displays alarming pop-up messages, often claiming the system is infected with a virus, to trick the user into calling a fake support number or purchasing unnecessary software. The pop-up is designed to be persistent and difficult to close, creating a sense of urgency to coerce the user into action. This matches the scenario exactly, as the user sees a virus warning pop-up that will not close and is instructed to call a number for assistance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ransomware
Why it's wrong here
Ransomware's primary goal is financial extortion via encryption of user data; it announces itself with a ransom note demanding payment, often with a countdown, but does not rely on fake infection pop-ups. The pop-up here is a lure to elicit action, not a post-encryption demand. Thus, while malicious, the mechanism and intent differ.
- ✗
Rootkit
Why it's wrong here
Rootkits operate at kernel or boot level to conceal malicious processes and files, giving attackers persistent undetected access. They avoid drawing attention to themselves, so a conspicuous pop-up claiming an infection would undermine their stealth. Rootkits don't typically generate user-facing alerts; they facilitate other malware silently.
- ✓
Scareware
Why this is correct
Scareware uses fabricated security alerts and pop-ups to trick users into believing their system is infected, often pressuring them to purchase bogus antivirus software or contact fraudulent tech support. The pop-up warning is the primary attack vector, exploiting urgency and fear to extract money or remote access. This matches the symptom precisely.
- ✗
Worm
Why it's wrong here
Worms self-replicate and spread across networks by exploiting vulnerabilities, often requiring no user interaction and targeting maximum host compromise. They rarely display persistent pop-ups; their presence is typically observed through network activity or performance degradation. A single warning dialog is a social-engineering tactic, not a worm's characteristic behavior.
Go deeper
Related to this question
Learn chapter
Malware Classification: Virus, Worm, Ransomware, Rootkit
Key term
Virus
A virus is a malicious software program that attaches itself to legitimate files or programs and spreads to other systems, often causing damage or stealing information.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.