A file server suddenly shows renamed files with a new extension, users see a ransom note demanding cryptocurrency, and shadow copies are deleted from the host. Which malware family is the best match?
Ransomware is the correct classification because the file server's symptoms—renamed files with a new extension—are the direct result of a bulk encryption routine, typically a hybrid of AES and RSA, that scrambles file contents and appends a distinctive marker. This malware family deliberately deletes volume shadow copies and backup catalogs to prevent simple restoration, then drops a ransom note with payment instructions, usually demanding cryptocurrency. The combination of systemic file encryption, renamed extensions, and extortion is the definitive signature of modern ransomware like LockBit, not a passive or stealthy infection.
Why this answer
Ransomware is the correct classification because the scenario describes file encryption (renamed files with new extensions), a ransom note demanding cryptocurrency, and the deletion of shadow copies (Volume Shadow Copy Service snapshots) to prevent file recovery. These are hallmark behaviors of ransomware, specifically crypto-ransomware, which encrypts data and demands payment for decryption keys.
Exam trap
The trap here is that candidates may confuse ransomware with a Trojan because both can be delivered via social engineering, but the defining behaviors of file encryption, ransom note, and shadow copy deletion are unique to ransomware, not generic malware types.
How to eliminate wrong answers
Option B is wrong because a Trojan is a type of malware that disguises itself as legitimate software to gain access, but it does not inherently perform file encryption or demand ransom; the described behaviors are specific to ransomware, not Trojans. Option C is wrong because spyware is designed to monitor user activity and steal information without the user's knowledge, not to encrypt files or display ransom notes; the deletion of shadow copies and file renaming are not spyware characteristics. Option D is wrong because a logic bomb is a piece of code that executes malicious actions when a specific condition is met (e.g., date or user action), but it does not typically involve file encryption, ransom notes, or cryptocurrency demands; the scenario lacks any trigger condition and instead shows active encryption and extortion.