Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

After a workstation reboot, users see many files renamed with random extensions. A ransom note demands cryptocurrency, and Volume Shadow Copies were deleted from the machine. What malware type is most likely?

⚠ Common exam trap

The trap here is that candidates see 'files renamed' and 'ransom note' but may confuse the delivery method (Trojan) or propagation (Worm) with the actual malware type, which is defined by its payload—encryption for extortion—not how it arrived or spread.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Ransomware, because the files were encrypted and payment was demanded.

The scenario describes files renamed with random extensions (indicating encryption), a ransom note demanding cryptocurrency, and deletion of Volume Shadow Copies (VSS) to prevent file recovery. These are hallmark behaviors of ransomware, specifically a crypto-ransomware variant that encrypts user data and removes backup copies to maximize extortion pressure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Trojan, because the malware may have been disguised as a legitimate application.

    Why it's wrong here

    A Trojan is a delivery category that describes malware tricking a user into running it, not a set of observable post-infection effects. Here the hard evidence—file encryption with random extensions, a ransom note, and deliberately purged shadow copies—directly matches the defined behavior of ransomware. While a trojan could absolutely be the initial vector that dropped this payload, the question asks which type of malware the symptoms identify, and those symptoms are the signature of ransomware extortion, not just deception.

  • Worm, because the malware likely spread automatically to other systems.

    Why it's wrong here

    Worms are fundamentally self-propagating malware that spreads autonomously across hosts via network services, email, or removable drives. The scenario gives no indication of lateral movement, automated replication, or other systems being affected—it only describes files on the local workstation being encrypted. Even though some ransomware families have worm-like spreading components, the core classification here is driven by the encryption-and-payment demand, not by any observed ability to move from system to system on its own.

  • Ransomware, because the files were encrypted and payment was demanded.

    Why this is correct

    Ransomware commonly encrypts files, deletes recovery options, and leaves a ransom note demanding payment. The random extensions and removed shadow copies are classic clues that the attacker wants to block restoration until payment is made.

  • Rootkit, because the attacker would want to hide persistence on the system.

    Why it's wrong here

    A rootkit is designed for stealth and persistent concealment, typically hooking operating system internals to hide processes, files, or registry keys from detection. Encrypting thousands of user files and dropping a ransom note is the opposite of stealthy behavior because it creates immediate, visible business impact and alerts the user to the compromise. The deletion of shadow copies is meant to block recovery and increase extortion pressure, not to hide the attacker's presence—so the evidence points to ransomware's denial-of-access tactic rather than rootkit-style covert access.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.