CEH Practice Question: Malware, Social Engineering and Network Attacks
Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?
⚠ Common exam trap
A common mix-up: candidates confuse ransomware with other malware types that also cause damage or demand payment, but only ransomware specifically encrypts files for extortion, not for data theft or advertising.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
Ransomware is the correct answer because it specifically encrypts files on the victim's system using a symmetric encryption algorithm (e.g., AES) and then demands a ransom payment, typically in cryptocurrency, to provide the decryption key. This distinguishes it from other malware types that do not perform file encryption for extortion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spyware
Why it's wrong here
Spyware covertly collects user activity, credentials or keystrokes and forwards them to an attacker; it does not encrypt files or demand payment. It is tempting because spyware is a common malware classification, but its purpose is surveillance and data exfiltration, making it correct only when the stem describes hidden monitoring rather than extortion.
- ✗
Adware
Why it's wrong here
Adware injects unwanted advertisements into browser sessions or applications; it neither encrypts files nor holds data to ransom. It is tempting because adware is a recognised malware category that generates revenue for its operator, but that revenue comes from advertising impressions, not extortion, so it would be the answer only if the stem described pop-ups or hijacked search results.
- ✗
Keylogger
Why it's wrong here
A keylogger captures keystrokes to steal credentials and other typed data; it performs no file encryption and issues no ransom demand. It is tempting because keyloggers are frequently bundled with other malware, but their mechanism is input capture, so a keylogger would be the answer only if the stem described credential theft via recorded typing.
- ✓
Ransomware
Why this is correct
Ransomware encrypts victim files using symmetric or asymmetric cryptography and holds the decryption key hostage, demanding payment for its release. This matches the stem's encryption-plus-payment mechanism precisely, distinguishing it from worms, trojans or spyware, which do not extort via encryption.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.