SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A help desk technician reports several workstations are suddenly showing lots of pop-up ads and browser redirects after users installed a free media player. What type of unwanted software is most likely present?
⚠ Common exam trap
Test-takers frequently confuse the symptoms of adware with ransomware or a rootkit because pop-ups and redirects can sometimes be caused by more severe malware, but the specific context of a free media player installation points directly to adware as the most likely type of unwanted software.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adware
Adware is the most likely culprit because it is a type of unwanted software designed to display intrusive advertisements, often through pop-up ads and browser redirects. The infection vector—users installing a free media player—is a classic distribution method for adware, which bundles itself with legitimate software to generate revenue via ad impressions. Unlike ransomware or rootkits, adware does not encrypt files or hide its presence; it directly manipulates browser sessions to serve ads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ransomware
Why it's wrong here
Ransomware is specifically designed to encrypt a victim's files or lock the entire system, demanding a ransom payment for the decryption key or access restoration. While ransomware often displays a full-screen ransom note, it does not cause repeated pop-up ads or browser redirects; its primary observable impact is denial of access to data, not persistent advertising.
- ✓
Adware
Why this is correct
Adware is a type of malicious software that automatically delivers unwanted advertisements, typically through pop-ups, browser redirects, and injected banners. It often installs without explicit user consent or as part of a bundled download, and its presence is characterized by the sudden, frequent display of ads across multiple workstations—exactly the behavior described in the scenario.
- ✗
Rootkit
Why it's wrong here
A rootkit is a covert malware type designed to hide its own presence and other malicious processes by intercepting and modifying operating system functions, such as system calls or kernel modules. Its goal is to maintain stealthy, privileged access for an attacker, and it does not produce visible pop-up ads; in fact, rootkits actively avoid drawing attention to their activities, making ad-driven behavior inconsistent with their purpose.
- ✗
Logic bomb
Why it's wrong here
A logic bomb is a piece of malicious code that remains dormant until a specific condition—such as a date, time, or user action—is met, then triggers a harmful payload like data deletion or system disruption. It does not continuously execute to display pop-ups or redirect web traffic; instead, it is characterized by a single, conditional detonation, which does not match the ongoing adware-like symptoms observed on the workstations.
Go deeper
Related to this question
Learn chapter
Ransomware Attacks
Key term
Adware
Adware is software that automatically displays or downloads unwanted advertisements, often bundled with free programs, and may track user behavior without clear consent.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.