Courseiva
Security →mediumMultiple Choice

FC0-U71 Security Practice Question

An employee at a marketing firm plugs an unknown USB flash drive found in the parking lot into a workstation to identify its owner. Within minutes, files on a shared network folder begin to be renamed with a .locked extension and a ransom note appears. Which type of malware most likely caused this behavior?

⚠ Common exam trap

The trap here is focusing on the USB delivery method and choosing a propagation category, when the observed file encryption and ransom note identify the payload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ransomware

The telltale signs are files renamed with a new extension and a ransom note demanding payment, which are the defining behaviors of ransomware. Ransomware often arrives via removable media and then enumerates mapped drives and network shares to encrypt as many files as possible. Other malware types may be involved in delivery, but the destructive encryption and extortion identify the payload itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Keylogger

    Why it's wrong here

    A keylogger records keystrokes to capture credentials and other typed data, then exfiltrates them to an attacker. It operates quietly and does not encrypt or rename files, nor does it leave a ransom note. The destructive, visible file changes on the shared folder fall outside a keylogger's behavior, making this choice incorrect for the scenario.

  • ✗

    Worm

    Why it's wrong here

    A worm self-replicates across networks without user interaction, consuming bandwidth and spreading to new hosts. While a worm may carry a ransomware payload, the worm itself does not rename files or demand payment. The defining evidence here is encryption and extortion, which point to the payload rather than the propagation mechanism, so worm is not the most accurate answer.

  • ✗

    Rootkit

    Why it's wrong here

    A rootkit hides itself and other malware deep in the operating system, often at the kernel or boot level, to evade detection. It does not typically rename user files or display ransom demands; its purpose is stealth and persistence. The visible mass renaming and extortion note are overt actions inconsistent with a rootkit's concealment goal, so this is not the best classification.

  • ✓

    Ransomware

    Why this is correct

    Ransomware encrypts files and appends a distinctive extension such as .locked, then displays a note demanding payment for the decryption key. The rapid spread from one workstation to a shared network folder matches ransomware that enumerates mapped drives and network shares. The vehicle being a found USB drive is a classic delivery method, but the file-renaming and ransom note identify the payload as ransomware.

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.