SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A user says their files suddenly have a new extension and a note appears demanding payment to restore access. Which type of malware is most likely involved?
⚠ Common exam trap
Many exam-takers confuse ransomware with adware or other malware types, but the key differentiator is the combination of file encryption, extension change, and a ransom demand.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
Ransomware is the correct answer because it specifically encrypts files and appends a new extension, then displays a ransom note demanding payment for decryption. This matches the user's description of files becoming inaccessible with a new extension and a payment demand.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ransomware
Why this is correct
Crypto-ransomware, such as the notorious Ryuk or LockBit variants, encrypts user files using symmetric algorithms like AES, then appends a unique extension to each affected file to mark it as compromised. A ransom note is then dropped in each directory, instructing the victim to pay a cryptocurrency ransom in exchange for the decryption key, which perfectly matches the sudden file extension and note appearance described.
- ✗
Adware
Why it's wrong here
Adware is a form of monetization that primarily seeks to display unwanted advertisements, often through browser pop-ups, injected banners, or redirects, to generate revenue for its developers. Unlike ransomware, adware lacks the mechanism to encrypt files or alter their extensions, and it does not demand payment to restore data. While adware is intrusive, the symptom of encrypted files with new extensions and a recovery-demand note is fundamentally inconsistent with adware's operational behavior.
- ✗
Spam filter
Why it's wrong here
A spam filter is a defensive security control, typically integrated into email servers or clients, that analyzes incoming messages for malicious content or unsolicited bulk mail and quarantines or blocks them. It is not a malware program and does not execute code on a user's local file system, nor does it have any capability to encrypt files or change their extensions. The described symptoms—encrypted files and a ransom note—cannot be caused by a spam filter; at most, a spam filter might fail to block the initial phishing email that delivers ransomware, but the filter itself is not the source of the attack.
- ✗
Screen saver
Why it's wrong here
A screen saver is a simple display application that activates when a system is idle, primarily to prevent phosphor burn-in on older CRT monitors or to lock the workstation for security. By itself, a screen saver cannot interact with the file system to read, modify, or encrypt user data, and it would never generate a ransom note demanding payment. Even if a malicious actor replaced a screen saver with malware, the screen saver is merely the delivery mechanism; the actual cause would be the ransomware, not the screen saver itself, making this option wholly incorrect.
Go deeper
Related to this question
Learn chapter
Malware Types and Characteristics
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.