SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A laptop user reports that many files now have strange extensions, a ransom note appears on the desktop, and the files cannot be opened. Which malware is most likely responsible?
⚠ Common exam trap
Many candidates confuse ransomware with a worm because both can spread rapidly, but the key differentiator is the ransom note and file encryption, which are unique to ransomware.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
Ransomware is the correct answer because it encrypts the user's files, appends a new extension (e.g., .encrypted or .locked), and displays a ransom note demanding payment for the decryption key. The symptoms of inaccessible files with altered extensions and a visible ransom note are the classic indicators of a ransomware infection, such as those caused by CryptoLocker or LockBit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spyware
Why it's wrong here
Spyware is designed to covertly monitor a user's activity—capturing keystrokes, browsing history, and login credentials—and transmit that data to a remote attacker. It focuses on stealthy data exfiltration and typically does not alter file integrity or rename files. The sudden appearance of unusual file extensions and a ransom demand indicates encryption-oriented malware, not a surveillance-focused spyware.
- ✓
Ransomware
Why this is correct
Ransomware is a type of extortion malware that encrypts a victim's files with a strong cryptographic algorithm (often a combination of AES and RSA) and then appends a distinctive extension to each encrypted file, such as .lock or .polysafe. Following encryption, it drops a ransom note containing payment instructions, usually demanding cryptocurrency in exchange for the decryption key. The user's report of 'strange file extensions' and widespread file corruption is the classic indicator that ransomware has executed a local encryption payload, rather than merely collecting information or hiding in the system.
- ✗
Rootkit
Why it's wrong here
A rootkit operates at the lowest levels of the system—such as the kernel, hypervisor, or boot loader—to achieve elevated privileges and stealthy persistence while masking malicious activities from standard housekeeping tools. It is engineered to hide itself and other malware, not to draw attention by renaming files or displaying ransom notices. Since the user is noticing obvious file changes and an extortion demand, this behavior is antithetical to a rootkit's primary objective of covert concealment.
- ✗
Worm
Why it's wrong here
A worm is a standalone self-replicating program that spreads across networks by exploiting vulnerabilities or using social engineering techniques, often without any user interaction. While a worm can deliver a destructive payload, its hallmark is resource consumption and network propagation, not the deliberate encryption and renaming of local files with a ransom message. The visible ransom demand and strange extensions point to malware whose immediate goal is financial extortion via data encryption—a behavior characteristic of ransomware, not a worm's auto-spreading mechanism.
Go deeper
Related to this question
Learn chapter
Malware Types and Characteristics
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.