After installing a free utility from an unofficial website, a user's laptop starts quietly sending browsing data to an unknown server. What type of malware is most likely present?
Spyware is a type of malicious software that covertly monitors user activity and transmits that information to a remote attacker. In this scenario, quietly harvesting browsing data is a hallmark behavior of spyware, which often arrives bundled with free utilities from unofficial sources. Unlike outright destructive malware, spyware focuses on data exfiltration and typically operates in the background without the user's knowledge, making it the best match for the described symptoms.
Why this answer
Spyware is designed to covertly collect user data, such as browsing habits, and transmit it to a remote server without consent. The scenario describes a free utility from an unofficial website that quietly exfiltrates browsing data, which is the classic behavior of spyware. Unlike other malware types, spyware focuses on surveillance and data theft rather than system damage or self-replication.
Exam trap
The trap here is that candidates may confuse spyware with a rootkit because both can operate stealthily, but the key differentiator is the primary objective: spyware focuses on data theft, while a rootkit focuses on hiding other malware or maintaining persistent access.
How to eliminate wrong answers
Option B is wrong because ransomware encrypts files or locks the system to demand a ransom, not to quietly exfiltrate browsing data. Option C is wrong because a worm self-replicates across networks without user interaction, whereas this infection required manual installation of a utility. Option D is wrong because a rootkit hides its presence by subverting OS-level functions (e.g., hooking system calls), but the described symptom—data exfiltration—is not the defining trait; spyware is the more direct classification for data theft.