FC0-U71 Security Practice Question
An employee at a marketing firm plugs an unknown USB flash drive found in the parking lot into a workstation to identify its owner. Within minutes, files on a shared network folder begin to be renamed with a .locked extension and a ransom note appears. Which type of malware most likely caused this behavior?
⚠ Common exam trap
The trap here is focusing on the USB delivery method and choosing a propagation category, when the observed file encryption and ransom note identify the payload.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
The telltale signs are files renamed with a new extension and a ransom note demanding payment, which are the defining behaviors of ransomware. Ransomware often arrives via removable media and then enumerates mapped drives and network shares to encrypt as many files as possible. Other malware types may be involved in delivery, but the destructive encryption and extortion identify the payload itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Keylogger
Why it's wrong here
A keylogger records keystrokes to capture credentials and other typed data, then exfiltrates them to an attacker. It operates quietly and does not encrypt or rename files, nor does it leave a ransom note. The destructive, visible file changes on the shared folder fall outside a keylogger's behavior, making this choice incorrect for the scenario.
- ✗
Worm
Why it's wrong here
A worm self-replicates across networks without user interaction, consuming bandwidth and spreading to new hosts. While a worm may carry a ransomware payload, the worm itself does not rename files or demand payment. The defining evidence here is encryption and extortion, which point to the payload rather than the propagation mechanism, so worm is not the most accurate answer.
- ✗
Rootkit
Why it's wrong here
A rootkit hides itself and other malware deep in the operating system, often at the kernel or boot level, to evade detection. It does not typically rename user files or display ransom demands; its purpose is stealth and persistence. The visible mass renaming and extortion note are overt actions inconsistent with a rootkit's concealment goal, so this is not the best classification.
- ✓
Ransomware
Why this is correct
Ransomware encrypts files and appends a distinctive extension such as .locked, then displays a note demanding payment for the decryption key. The rapid spread from one workstation to a shared network folder matches ransomware that enumerates mapped drives and network shares. The vehicle being a found USB drive is a classic delivery method, but the file-renaming and ransom note identify the payload as ransomware.
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.