FC0-U71 Security Practice Question
Which TWO of the following are characteristics of ransomware?
⚠ Common exam trap
FC0-U71 often tests whether candidates can distinguish ransomware from adjacent malware categories — spyware, worms, and Trojans — by focusing on the payment demand and file encryption as the defining pair of traits.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It encrypts the victim's files.
Option C is correct because the defining behavior of ransomware is that it encrypts the victim's files (often using strong symmetric ciphers like AES with a per-file key, then wrapping that key with asymmetric encryption such as RSA), rendering the data inaccessible until a key is provided. Option D is correct because ransomware is a form of extortion: after encryption it presents a ransom note demanding payment, typically in cryptocurrency such as Bitcoin or Monero, in exchange for the decryption key or tool. Option A describes spyware, which covertly harvests user information rather than encrypting and holding data hostage. Option B describes a worm, which propagates across systems autonomously without user interaction, a spreading mechanism rather than the extortion characteristic of ransomware. Option E describes a Trojan, which masquerades as legitimate software to trick users into running it, and while ransomware is often delivered via Trojans, disguise is not its defining characteristic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It collects user information without consent.
Why it's wrong here
Spyware, not ransomware, gathers user data covertly; ransomware encrypts files and demands payment for the decryption key, so this fails the scenario's defining trait. It tempts because both are malicious payloads delivered via phishing or exploits, and spyware would be the right answer if the question asked about covert surveillance or credential harvesting.
- ✗
It self-replicates to other systems without user interaction.
Why it's wrong here
Self-replication without user interaction is the defining propagation mechanism of worms, which spread autonomously across networks. Ransomware typically relies on phishing, exploited vulnerabilities or manual intrusion, then encrypts files and demands payment; it does not self-propagate.
- ✓
It encrypts the victim's files.
Why this is correct
Ransomware encrypts the victim's files using symmetric keys, rendering documents, databases and images inaccessible until decryption occurs. This cryptographic locking is the defining characteristic that distinguishes ransomware from other malware, and it directly satisfies the stem's requirement for a ransomware trait.
- ✓
It demands payment in exchange for decryption.
Why this is correct
Ransomware operators demand payment, typically in cryptocurrency, in exchange for the decryption key or tool. This extortion demand is a defining characteristic of ransomware, satisfying the stem's requirement, and it distinguishes ransomware from malware that simply destroys or exfiltrates data.
- ✗
It disguises itself as legitimate software.
Why it's wrong here
Disguising itself as legitimate software describes a trojan, which relies on user deception to execute; ransomware instead encrypts files and demands payment, often after silent lateral movement. It is tempting because ransomware is frequently delivered via trojan droppers, but the disguise is the delivery vector, not the defining characteristic.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 988 original FC0-U71 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.