SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
After a workstation reboot, users see many files renamed with random extensions. A ransom note demands cryptocurrency, and Volume Shadow Copies were deleted from the machine. What malware type is most likely?
⚠ Common exam trap
The trap here is that candidates see 'files renamed' and 'ransom note' but may confuse the delivery method (Trojan) or propagation (Worm) with the actual malware type, which is defined by its payload—encryption for extortion—not how it arrived or spread.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware, because the files were encrypted and payment was demanded.
The scenario describes files renamed with random extensions (indicating encryption), a ransom note demanding cryptocurrency, and deletion of Volume Shadow Copies (VSS) to prevent file recovery. These are hallmark behaviors of ransomware, specifically a crypto-ransomware variant that encrypts user data and removes backup copies to maximize extortion pressure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trojan, because the malware may have been disguised as a legitimate application.
Why it's wrong here
A Trojan is a delivery category that describes malware tricking a user into running it, not a set of observable post-infection effects. Here the hard evidence—file encryption with random extensions, a ransom note, and deliberately purged shadow copies—directly matches the defined behavior of ransomware. While a trojan could absolutely be the initial vector that dropped this payload, the question asks which type of malware the symptoms identify, and those symptoms are the signature of ransomware extortion, not just deception.
- ✗
Worm, because the malware likely spread automatically to other systems.
Why it's wrong here
Worms are fundamentally self-propagating malware that spreads autonomously across hosts via network services, email, or removable drives. The scenario gives no indication of lateral movement, automated replication, or other systems being affected—it only describes files on the local workstation being encrypted. Even though some ransomware families have worm-like spreading components, the core classification here is driven by the encryption-and-payment demand, not by any observed ability to move from system to system on its own.
- ✓
Ransomware, because the files were encrypted and payment was demanded.
Why this is correct
Ransomware commonly encrypts files, deletes recovery options, and leaves a ransom note demanding payment. The random extensions and removed shadow copies are classic clues that the attacker wants to block restoration until payment is made.
- ✗
Rootkit, because the attacker would want to hide persistence on the system.
Why it's wrong here
A rootkit is designed for stealth and persistent concealment, typically hooking operating system internals to hide processes, files, or registry keys from detection. Encrypting thousands of user files and dropping a ransom note is the opposite of stealthy behavior because it creates immediate, visible business impact and alerts the user to the compromise. The deletion of shadow copies is meant to block recovery and increase extortion pressure, not to hide the attacker's presence—so the evidence points to ransomware's denial-of-access tactic rather than rootkit-style covert access.
Go deeper
Related to this question
Learn chapter
Malware Types and Characteristics
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.