SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A file server suddenly renames documents with a new extension and displays a note demanding payment in cryptocurrency to restore access. What type of malware is most likely involved?
⚠ Common exam trap
It's easy for candidates to confuse ransomware with other malware types that alter files or display messages, but only ransomware specifically encrypts files and demands a ransom for decryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
Ransomware is designed to encrypt files on a system, making them inaccessible, and then demand a ransom—typically in cryptocurrency—to restore access. The sudden renaming of documents with a new extension is a hallmark of ransomware encryption, as it appends a custom extension to indicate the files have been locked. The displayed note demanding payment confirms the extortion motive, which is unique to ransomware among the given options.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ransomware
Why this is correct
This is the classic symptom pattern for ransomware. Files are renamed or encrypted, access is disrupted, and the attacker demands payment for recovery. The ransom note and the sudden file changes together make ransomware the best answer.
- ✗
Spyware
Why it's wrong here
Spyware is designed for covert surveillance, harvesting credentials, keystrokes, and sensitive data while remaining undetected. Its primary goal is to maintain stealth and persistent access to exfiltrate information, not to disrupt operations. Suddenly renaming files and leaving a ransom note would directly expose its presence and undermine its intelligence-gathering mission, which is the opposite of spyware's typical silent behavior.
- ✗
Worm
Why it's wrong here
A worm is a self-propagating piece of malware that autonomously spreads across networks by exploiting vulnerabilities, with its core objective being replication and distribution. While some ransomware families use worm-like propagation, the symptom described—sudden file renames and a ransom demand—points to extortion, not self-replication. A traditional worm focuses on consuming network resources or delivering payloads, but it does not inherently encrypt files and demand payment, making it a wrong classification for this scenario.
- ✗
Rootkit
Why it's wrong here
A rootkit is a stealthy toolset that provides attackers with privileged, hidden access to a system, often by hooking kernel functions or replacing system binaries to conceal malicious activity. Its fundamental purpose is to remain invisible and persist over time, enabling backdoor access or hiding other malware. Renaming documents and demanding a ransom would be glaringly conspicuous, directly contradicting a rootkit's need for concealment; such overt extortion is characteristic of ransomware, not a rootkit.
Go deeper
Related to this question
Learn chapter
Malware Types and Characteristics
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.