Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

After a user installs a free PDF converter from an unofficial website, the laptop starts making periodic outbound connections to an unknown server, the browser homepage changes, and a new program launches at logon. What is the most likely malware type?

⚠ Common exam trap

Candidates often confuse the self-replicating behavior of a worm with the user-initiated installation of a Trojan, or mistake the visible symptoms (browser change, startup entry) for a rootkit's stealth, when in fact Trojans often exhibit overt persistence mechanisms to maintain access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Trojan

The user downloaded and installed a program that appears legitimate (a PDF converter) but performs malicious actions: making outbound connections, changing browser settings, and adding a startup program. This is the classic behavior of a Trojan horse, which disguises itself as useful software to trick users into installing it, then executes hidden malicious functions. Unlike worms, Trojans do not self-replicate, and unlike ransomware or rootkits, the described symptoms focus on unauthorized remote access and persistence rather than file encryption or deep OS concealment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Worm

    Why it's wrong here

    A worm is a type of malware that self-replicates and autonomously propagates across networks, often by exploiting vulnerabilities or using built-in spreading mechanisms. In this scenario, there is no mention of the malware copying itself to other hosts or traversing the local network; the symptoms are confined to a single infected laptop. The original infection vector—a deceptive free utility—is a hallmark of a trojan, not a worm. Since the malware lacks the ability to move laterally or self-distribute, it does not qualify as a worm.

  • Trojan

    Why this is correct

    This is the best answer because the malicious software was disguised as a useful free tool. The symptoms include persistence, browser changes, and communication with an unknown server, which are common signs of a trojan payload. Trojans often arrive through deceptive downloads and then install additional harmful behavior after execution.

  • Rootkit

    Why it's wrong here

    A rootkit is designed to hide its own presence and maintain privileged, stealthy access by intercepting operating system APIs, modifying kernel data structures, or replacing system tools. The visible symptoms described—browser homepage changes, persistence, and communication with an unknown server—are user-observable and disruptive, which contradicts the stealth-oriented nature of a rootkit. While a trojan could later install a rootkit as a secondary payload to conceal itself, the primary behavior in this scenario aligns with the trojan's deceptive delivery and payload symptoms. Without evidence of OS-level concealment or kernel-level manipulation, rootkit is not the correct classification.

  • Ransomware

    Why it's wrong here

    Ransomware is defined by its method of extorting money: it typically encrypts user files or locks the entire screen, then demands payment to restore access. In this scenario, there is no indication of file encryption, a lockout screen, or a ransom note, so the attack's motive does not appear to be data destruction or denial of access. The symptoms—browser hijacking, persistence, and beaconing to an unknown server—point to a trojan that may be exfiltrating data or enabling remote access. While a trojan can serve as a delivery vector for ransomware, the absence of any encryption or ransom demand makes that classification unsupported here.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.