Courseiva
Malware, Social Engineering and Network AttackseasyMultiple SelectObjective-mapped

Ransomware and Scareware: Malware That Asks for Money

Which TWO of the following are types of malware that specifically aim to demand payment from victims?

Quick Answer

The answer is ransomware and scareware. Ransomware is a type of malware that encrypts a victim’s files or locks their system, then demands a monetary payment—often in cryptocurrency—in exchange for restoring access. Scareware, on the other hand, bombards the user with alarming pop-ups or fake system warnings claiming their computer is infected, pressuring them to pay for unnecessary or fraudulent security software. On the Certified Ethical Hacker CEH exam, this distinction tests your understanding of malware classification and attack vectors, often appearing in questions about threat types or social engineering tactics. A common trap is confusing scareware with adware, but remember: scareware explicitly demands payment for a fake fix, while adware simply displays ads. A useful memory tip is to think of “ransom” as holding data hostage and “scare” as using fear to trick you into paying.

⚠ Common exam trap

EC-CEH often tests the distinction between malware that demands payment (scareware and ransomware) versus malware that simply annoys or spies (adware, spyware, keyloggers), so candidates mistakenly classify scareware as a form of adware or spyware instead of recognizing its extortion-based goal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Scareware

Scareware is a type of malware that displays fake security alerts or warnings to trick users into believing their system is infected, then demands payment to remove the nonexistent threat. Ransomware encrypts the victim's files or locks the system and demands a ransom payment for decryption or restoration. Both specifically aim to extort money from victims.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Keylogger

    Why it's wrong here

    Keylogger records keystrokes, not demand payment.

  • Spyware

    Why it's wrong here

    Spyware secretly gathers information, not demand payment.

  • Scareware

    Why this is correct

    Scareware displays fake alerts to trick users into paying for removal.

  • Ransomware

    Why this is correct

    Ransomware demands payment for decryption key.

  • Adware

    Why it's wrong here

    Adware displays unwanted ads, not demand payment.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which type of malware encrypts the victim's files and demands payment for the decryption key?

easy
  • A.Keylogger
  • B.Spyware
  • C.Adware
  • D.Ransomware

Why D: Ransomware is the correct answer because it specifically encrypts the victim's files using symmetric encryption (e.g., AES) and then demands a ransom payment, typically in cryptocurrency, in exchange for the decryption key. Unlike other malware types, its primary purpose is data hostage for financial extortion, often leveraging asymmetric encryption (e.g., RSA) to secure the symmetric key.

Variation 2. Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?

easy
  • A.Spyware
  • B.Adware
  • C.Keylogger
  • D.Ransomware

Why D: Ransomware is the correct answer because it specifically encrypts files on the victim's system using a symmetric encryption algorithm (e.g., AES) and then demands a ransom payment, typically in cryptocurrency, to provide the decryption key. This distinguishes it from other malware types that do not perform file encryption for extortion.

Variation 3. Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?

easy
  • A.Ransomware
  • B.Trojan
  • C.Spyware
  • D.Adware

Why A: Ransomware is specifically designed to encrypt files on a victim's system using strong cryptographic algorithms (e.g., AES-256 for symmetric encryption, often paired with RSA-2048 for key exchange). After encryption, the malware displays a ransom note demanding payment (typically in cryptocurrency like Bitcoin) in exchange for the decryption key. This matches the description exactly, making option A correct.

Variation 4. Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?

easy
  • A.Ransomware
  • B.Spyware
  • C.Keylogger
  • D.Adware

Why A: Ransomware is a type of malware that encrypts files on the victim's system using a symmetric encryption algorithm (e.g., AES) and then demands payment, typically in cryptocurrency, for the decryption key. This matches the description of encrypting files and demanding payment for the decryption key, which is the defining characteristic of ransomware.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.