SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
Exhibit
Help desk incident notes: - User installed a free video converter from an unofficial download site. - Browser home page changed without permission. - A new extension appeared named "QuickSearch Helper". - Outbound traffic to tracking.example-cdn.net increased every few minutes. - The endpoint security console reports that saved browser cookies were accessed by an unknown process.
Based on the exhibit, what type of malware is the most likely issue on the workstation?
⚠ Common exam trap
Many exam-takers confuse the symptom of changed browser settings with ransomware, but ransomware's primary action is file encryption or system lockout, not silent data collection, and the unofficial website installation is a red herring for worm propagation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spyware, because the system appears to be collecting user data silently.
The exhibit shows a browser extension installed from an unofficial website that is silently collecting browsing data, including keystrokes and visited URLs, which is characteristic of spyware. Spyware operates by gathering user information without consent, often through seemingly legitimate software, and the absence of encryption or user notification confirms this classification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Spyware, because the system appears to be collecting user data silently.
Why this is correct
Spyware is the best fit because the symptoms show covert data collection and tracking behavior. The unwanted browser extension, the repeated outbound traffic to a tracking domain, and the access to saved cookies all point to surveillance and data theft rather than encryption or destructive behavior.
- ✗
Ransomware, because the browser settings changed after installation.
Why it's wrong here
Ransomware is primarily characterized by file encryption, system lockdown, and an extortion demand for payment. A change to browser settings, such as a homepage redirect or an injected extension, is a hallmark of browser hijackers or potentially unwanted programs (PUPs), not ransomware. The exhibit shows no evidence of encrypted files, a locked screen, or a ransom note; instead, the traffic to a tracking domain and silent access to saved cookies indicate covert data collection. Thus, the observed behavior aligns with spyware, not ransomware.
- ✗
Rootkit, because the endpoint security console detected an unknown process.
Why it's wrong here
A rootkit is purpose-built to conceal its presence by intercepting system or kernel-level calls to hide processes, files, and network connections from the operating system and security tools. If this were a rootkit, the endpoint security console would likely not have detected the unknown process in the first place, as hiding from security software is a primary function of rootkits. The exhibit presents no evidence of kernel-mode hooking, driver tampering, or disabled security tools, only surveillance-like behavior such as outbound tracking traffic and cookie access. Therefore, the symptoms point to spyware rather than a stealthy privilege-escalation rootkit.
- ✗
Worm, because the software was installed from an unofficial website.
Why it's wrong here
Worms are self-replicating malware that spread independently across networks, typically through vulnerabilities, email attachments, or network shares, and do not rely on manual installation by a user. Downloading from an unofficial website is a common vector for delivering spyware or adware bundles, but it does not demonstrate the worm's defining ability to propagate on its own. The exhibit describes a manually installed suspicious utility that then silently accessed saved cookies and sent traffic to a tracking domain, which is behavior consistent with spyware, not worm propagation. The absence of networked spreading or self-replication confirms this is not a worm.
Go deeper
Related to this question
Learn chapter
Malware Types and Characteristics
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Spyware
Spyware is malicious software that secretly monitors and collects information about a user's activity without their knowledge or consent.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.