FC0-U71 Security Practice Question
Which TWO of the following are types of malware? (Select TWO)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
Ransomware (B) is a type of malware that encrypts a victim's files or locks a system and demands payment for restoration, making it a classic malicious software category. Spyware (E) is also malware, designed to covertly monitor user activity and harvest sensitive information such as credentials or browsing habits. A firewall (A) is a security control that filters network traffic, not malware. Encryption (C) is a legitimate cryptographic technique for protecting data confidentiality, not malicious software. Phishing (D) is a social-engineering attack that tricks users into revealing information, but it is an attack method rather than a malware type.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall
Why it's wrong here
A firewall is a network security control that filters traffic, not malicious software. It is tempting because firewalls and malware both feature in security discussions, but a firewall is the correct answer when the question asks for a defensive perimeter device.
- ✓
Ransomware
Why this is correct
Ransomware is malware that encrypts a victim's files or locks their system, then demands payment for the decryption key. This extortion mechanism, holding data hostage until a ransom is paid, places it squarely within the malware category the question asks candidates to identify.
- ✗
Encryption
Why it's wrong here
Encryption is a protective technique that renders data unreadable, not malicious code. It appears plausible because ransomware uses encryption, yet encryption itself is a legitimate control and would be the right answer when asked how to protect data at rest or in transit.
- ✗
Phishing
Why it's wrong here
Phishing is a social-engineering attack that tricks users into revealing credentials, not malicious code executing on a host. It is tempting because phishing often delivers malware as an attachment or link, so it appears in the same threat landscape, but it would be the correct classification for a question asking about attack vectors rather than malware types.
- ✓
Spyware
Why this is correct
Spyware is malware that covertly monitors user activity, harvesting keystrokes, browsing habits, and credentials without consent. This stealthy surveillance and data-exfiltration behaviour defines it as malware, satisfying the question's requirement to select two malware types.
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.