Courseiva

CEH Practice Question: Malware, Social Engineering and Network Attacks

Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?

⚠ Common exam trap

A common mix-up: candidates confuse ransomware with other malware types that also cause damage or demand payment, but only ransomware specifically encrypts files for extortion, not for data theft or advertising.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ransomware

Ransomware is the correct answer because it specifically encrypts files on the victim's system using a symmetric encryption algorithm (e.g., AES) and then demands a ransom payment, typically in cryptocurrency, to provide the decryption key. This distinguishes it from other malware types that do not perform file encryption for extortion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Spyware

    Why it's wrong here

    Spyware covertly collects user activity, credentials or keystrokes and forwards them to an attacker; it does not encrypt files or demand payment. It is tempting because spyware is a common malware classification, but its purpose is surveillance and data exfiltration, making it correct only when the stem describes hidden monitoring rather than extortion.

  • ✗

    Adware

    Why it's wrong here

    Adware injects unwanted advertisements into browser sessions or applications; it neither encrypts files nor holds data to ransom. It is tempting because adware is a recognised malware category that generates revenue for its operator, but that revenue comes from advertising impressions, not extortion, so it would be the answer only if the stem described pop-ups or hijacked search results.

  • ✗

    Keylogger

    Why it's wrong here

    A keylogger captures keystrokes to steal credentials and other typed data; it performs no file encryption and issues no ransom demand. It is tempting because keyloggers are frequently bundled with other malware, but their mechanism is input capture, so a keylogger would be the answer only if the stem described credential theft via recorded typing.

  • ✓

    Ransomware

    Why this is correct

    Ransomware encrypts victim files using symmetric or asymmetric cryptography and holds the decryption key hostage, demanding payment for its release. This matches the stem's encryption-plus-payment mechanism precisely, distinguishing it from worms, trojans or spyware, which do not extort via encryption.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.