Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A file server suddenly shows renamed files with a new extension, users see a ransom note demanding cryptocurrency, and shadow copies are deleted from the host. Which malware family is the best match?

⚠ Common exam trap

Candidates often confuse ransomware with a Trojan because both can be delivered via social engineering, but the defining behaviors of file encryption, ransom note, and shadow copy deletion are unique to ransomware, not generic malware types.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Ransomware, because the attacker is encrypting data and demanding payment to restore access.

Ransomware is the correct classification because the scenario describes file encryption (renamed files with new extensions), a ransom note demanding cryptocurrency, and the deletion of shadow copies (Volume Shadow Copy Service snapshots) to prevent file recovery. These are hallmark behaviors of ransomware, specifically crypto-ransomware, which encrypts data and demands payment for decryption keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Ransomware, because the attacker is encrypting data and demanding payment to restore access.

    Why this is correct

    Ransomware is the correct classification because the file server's symptoms—renamed files with a new extension—are the direct result of a bulk encryption routine, typically a hybrid of AES and RSA, that scrambles file contents and appends a distinctive marker. This malware family deliberately deletes volume shadow copies and backup catalogs to prevent simple restoration, then drops a ransom note with payment instructions, usually demanding cryptocurrency. The combination of systemic file encryption, renamed extensions, and extortion is the definitive signature of modern ransomware like LockBit, not a passive or stealthy infection.

  • Trojan, because the attack requires a disguised program to install itself.

    Why it's wrong here

    A trojan is a delivery mechanism that disguises itself as a benign application to trick a user into running it; it is a distribution vector, not the observed behavior itself. While a trojan could drop ransomware, the visible symptom of files being renamed with a new extension and locked points decisively to the ransomware payload, not to the trojan's deception. Without evidence of a disguised executable or user-invoked installer, the classification is based on the end-state behavior: data encryption and a ransom demand.

  • Spyware, because the attacker is likely trying to monitor file activity.

    Why it's wrong here

    Spyware operates under an entirely different set of objectives: it quietly monitors keystrokes, screenshots, browsing habits, or credentials, and exfiltrates that data to a remote attacker, all while leaving existing files intact. Renaming files and adding a new extension indicates destructive or coercive modification of data, which spyware avoids to maintain stealth and persistence. The presence of a ransom-style attack signature—locked files plus an extortion demand—contradicts the passive, collection-focused nature of spyware.

  • Logic bomb, because the malware likely triggered after a specific condition was met.

    Why it's wrong here

    A logic bomb is a piece of code that lies dormant until a specific condition or trigger, such as a date, a user action, or an internal counter, causes it to execute; however, the trigger alone does not define the malware's primary effect. In this scenario, the key indicator is not the timing or condition but the outcome: files are encrypted, renamed, and a ransom note appears—classic extortion behavior. Even if the ransomware was conditionally triggered, the correct classification is the payload family, ransomware, not the triggering mechanism.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.