Ransomware and Scareware: Malware That Asks for Money
Which TWO of the following are types of malware that specifically aim to demand payment from victims?
Quick Answer
The answer is ransomware and scareware. Ransomware is a type of malware that encrypts a victim’s files or locks their system, then demands a monetary payment—often in cryptocurrency—in exchange for restoring access. Scareware, on the other hand, bombards the user with alarming pop-ups or fake system warnings claiming their computer is infected, pressuring them to pay for unnecessary or fraudulent security software. On the Certified Ethical Hacker CEH exam, this distinction tests your understanding of malware classification and attack vectors, often appearing in questions about threat types or social engineering tactics. A common trap is confusing scareware with adware, but remember: scareware explicitly demands payment for a fake fix, while adware simply displays ads. A useful memory tip is to think of “ransom” as holding data hostage and “scare” as using fear to trick you into paying.
⚠ Common exam trap
EC-CEH often tests the distinction between malware that demands payment (scareware and ransomware) versus malware that simply annoys or spies (adware, spyware, keyloggers), so candidates mistakenly classify scareware as a form of adware or spyware instead of recognizing its extortion-based goal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scareware
Scareware is a type of malware that displays fake security alerts or warnings to trick users into believing their system is infected, then demands payment to remove the nonexistent threat. Ransomware encrypts the victim's files or locks the system and demands a ransom payment for decryption or restoration. Both specifically aim to extort money from victims.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Keylogger
Why it's wrong here
Keylogger records keystrokes, not demand payment.
- ✗
Spyware
Why it's wrong here
Spyware secretly gathers information, not demand payment.
- ✓
Scareware
Why this is correct
Scareware displays fake alerts to trick users into paying for removal.
- ✓
Ransomware
Why this is correct
Ransomware demands payment for decryption key.
- ✗
Adware
Why it's wrong here
Adware displays unwanted ads, not demand payment.
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which type of malware encrypts the victim's files and demands payment for the decryption key?
easy- A.Keylogger
- B.Spyware
- C.Adware
- ✓ D.Ransomware
Why D: Ransomware is the correct answer because it specifically encrypts the victim's files using symmetric encryption (e.g., AES) and then demands a ransom payment, typically in cryptocurrency, in exchange for the decryption key. Unlike other malware types, its primary purpose is data hostage for financial extortion, often leveraging asymmetric encryption (e.g., RSA) to secure the symmetric key.
Variation 2. Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?
easy- A.Spyware
- B.Adware
- C.Keylogger
- ✓ D.Ransomware
Why D: Ransomware is the correct answer because it specifically encrypts files on the victim's system using a symmetric encryption algorithm (e.g., AES) and then demands a ransom payment, typically in cryptocurrency, to provide the decryption key. This distinguishes it from other malware types that do not perform file encryption for extortion.
Variation 3. Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?
easy- ✓ A.Ransomware
- B.Trojan
- C.Spyware
- D.Adware
Why A: Ransomware is specifically designed to encrypt files on a victim's system using strong cryptographic algorithms (e.g., AES-256 for symmetric encryption, often paired with RSA-2048 for key exchange). After encryption, the malware displays a ransom note demanding payment (typically in cryptocurrency like Bitcoin) in exchange for the decryption key. This matches the description exactly, making option A correct.
Variation 4. Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?
easy- ✓ A.Ransomware
- B.Spyware
- C.Keylogger
- D.Adware
Why A: Ransomware is a type of malware that encrypts files on the victim's system using a symmetric encryption algorithm (e.g., AES) and then demands payment, typically in cryptocurrency, for the decryption key. This matches the description of encrypting files and demanding payment for the decryption key, which is the defining characteristic of ransomware.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.