Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A file server suddenly renames documents with a new extension and displays a note demanding payment in cryptocurrency to restore access. What type of malware is most likely involved?

⚠ Common exam trap

It's easy for candidates to confuse ransomware with other malware types that alter files or display messages, but only ransomware specifically encrypts files and demands a ransom for decryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Ransomware

Ransomware is designed to encrypt files on a system, making them inaccessible, and then demand a ransom—typically in cryptocurrency—to restore access. The sudden renaming of documents with a new extension is a hallmark of ransomware encryption, as it appends a custom extension to indicate the files have been locked. The displayed note demanding payment confirms the extortion motive, which is unique to ransomware among the given options.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Ransomware

    Why this is correct

    This is the classic symptom pattern for ransomware. Files are renamed or encrypted, access is disrupted, and the attacker demands payment for recovery. The ransom note and the sudden file changes together make ransomware the best answer.

  • Spyware

    Why it's wrong here

    Spyware is designed for covert surveillance, harvesting credentials, keystrokes, and sensitive data while remaining undetected. Its primary goal is to maintain stealth and persistent access to exfiltrate information, not to disrupt operations. Suddenly renaming files and leaving a ransom note would directly expose its presence and undermine its intelligence-gathering mission, which is the opposite of spyware's typical silent behavior.

  • Worm

    Why it's wrong here

    A worm is a self-propagating piece of malware that autonomously spreads across networks by exploiting vulnerabilities, with its core objective being replication and distribution. While some ransomware families use worm-like propagation, the symptom described—sudden file renames and a ransom demand—points to extortion, not self-replication. A traditional worm focuses on consuming network resources or delivering payloads, but it does not inherently encrypt files and demand payment, making it a wrong classification for this scenario.

  • Rootkit

    Why it's wrong here

    A rootkit is a stealthy toolset that provides attackers with privileged, hidden access to a system, often by hooking kernel functions or replacing system binaries to conceal malicious activity. Its fundamental purpose is to remain invisible and persist over time, enabling backdoor access or hiding other malware. Renaming documents and demanding a ransom would be glaringly conspicuous, directly contradicting a rootkit's need for concealment; such overt extortion is characteristic of ransomware, not a rootkit.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.