Courseiva
Security →easyMultiple Select

FC0-U71 Security Practice Question

Which TWO of the following are types of malware? (Select TWO)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ransomware

Ransomware (B) is a type of malware that encrypts a victim's files or locks a system and demands payment for restoration, making it a classic malicious software category. Spyware (E) is also malware, designed to covertly monitor user activity and harvest sensitive information such as credentials or browsing habits. A firewall (A) is a security control that filters network traffic, not malware. Encryption (C) is a legitimate cryptographic technique for protecting data confidentiality, not malicious software. Phishing (D) is a social-engineering attack that tricks users into revealing information, but it is an attack method rather than a malware type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Firewall

    Why it's wrong here

    A firewall is a network security control that filters traffic, not malicious software. It is tempting because firewalls and malware both feature in security discussions, but a firewall is the correct answer when the question asks for a defensive perimeter device.

  • ✓

    Ransomware

    Why this is correct

    Ransomware is malware that encrypts a victim's files or locks their system, then demands payment for the decryption key. This extortion mechanism, holding data hostage until a ransom is paid, places it squarely within the malware category the question asks candidates to identify.

  • ✗

    Encryption

    Why it's wrong here

    Encryption is a protective technique that renders data unreadable, not malicious code. It appears plausible because ransomware uses encryption, yet encryption itself is a legitimate control and would be the right answer when asked how to protect data at rest or in transit.

  • ✗

    Phishing

    Why it's wrong here

    Phishing is a social-engineering attack that tricks users into revealing credentials, not malicious code executing on a host. It is tempting because phishing often delivers malware as an attachment or link, so it appears in the same threat landscape, but it would be the correct classification for a question asking about attack vectors rather than malware types.

  • ✓

    Spyware

    Why this is correct

    Spyware is malware that covertly monitors user activity, harvesting keystrokes, browsing habits, and credentials without consent. This stealthy surveillance and data-exfiltration behaviour defines it as malware, satisfying the question's requirement to select two malware types.

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.