Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A laptop user reports that many files now have strange extensions, a ransom note appears on the desktop, and the files cannot be opened. Which malware is most likely responsible?

⚠ Common exam trap

Many candidates confuse ransomware with a worm because both can spread rapidly, but the key differentiator is the ransom note and file encryption, which are unique to ransomware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Ransomware

Ransomware is the correct answer because it encrypts the user's files, appends a new extension (e.g., .encrypted or .locked), and displays a ransom note demanding payment for the decryption key. The symptoms of inaccessible files with altered extensions and a visible ransom note are the classic indicators of a ransomware infection, such as those caused by CryptoLocker or LockBit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Spyware

    Why it's wrong here

    Spyware is designed to covertly monitor a user's activity—capturing keystrokes, browsing history, and login credentials—and transmit that data to a remote attacker. It focuses on stealthy data exfiltration and typically does not alter file integrity or rename files. The sudden appearance of unusual file extensions and a ransom demand indicates encryption-oriented malware, not a surveillance-focused spyware.

  • Ransomware

    Why this is correct

    Ransomware is a type of extortion malware that encrypts a victim's files with a strong cryptographic algorithm (often a combination of AES and RSA) and then appends a distinctive extension to each encrypted file, such as .lock or .polysafe. Following encryption, it drops a ransom note containing payment instructions, usually demanding cryptocurrency in exchange for the decryption key. The user's report of 'strange file extensions' and widespread file corruption is the classic indicator that ransomware has executed a local encryption payload, rather than merely collecting information or hiding in the system.

  • Rootkit

    Why it's wrong here

    A rootkit operates at the lowest levels of the system—such as the kernel, hypervisor, or boot loader—to achieve elevated privileges and stealthy persistence while masking malicious activities from standard housekeeping tools. It is engineered to hide itself and other malware, not to draw attention by renaming files or displaying ransom notices. Since the user is noticing obvious file changes and an extortion demand, this behavior is antithetical to a rootkit's primary objective of covert concealment.

  • Worm

    Why it's wrong here

    A worm is a standalone self-replicating program that spreads across networks by exploiting vulnerabilities or using social engineering techniques, often without any user interaction. While a worm can deliver a destructive payload, its hallmark is resource consumption and network propagation, not the deliberate encryption and renaming of local files with a ransom message. The visible ransom demand and strange extensions point to malware whose immediate goal is financial extortion via data encryption—a behavior characteristic of ransomware, not a worm's auto-spreading mechanism.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.