CEH Ransomware Practice Question
Which type of malware is designed to encrypt files on a victim's system and demand payment for the decryption key?
⚠ Common exam trap
Test-takers frequently confuse ransomware with spyware or adware because all three are types of malware, but only ransomware specifically uses file encryption as a mechanism for extortion, not data theft or advertising.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
Ransomware is a type of malware that encrypts files on the victim's system using a symmetric encryption algorithm (e.g., AES) and then demands payment, typically in cryptocurrency, for the decryption key. This matches the description of encrypting files and demanding payment for the decryption key, which is the defining characteristic of ransomware.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ransomware
Why this is correct
Ransomware employs asymmetric encryption to lock files with a public key while the private decryption key remains solely with the attacker, directly satisfying the stem’s constraint of demanding payment for decryption. This contrasts with other malware types that may delete, exfiltrate, or corrupt data without encrypting it for ransom.
- ✗
Spyware
Why it's wrong here
Spyware covertly collects user activity and exfiltrates it; it holds no cryptographic mechanism to lock files or extort payment. It is tempting because both are intrusive payloads, and spyware would be the correct answer where the scenario describes credential theft or keystroke monitoring instead.
- ✗
Keylogger
Why it's wrong here
A keylogger captures keystrokes to steal credentials or messages; it contains no encryption routine to render files inaccessible or demand ransom. It is tempting because it is stealthy data-theft malware, and it would be correct where the scenario describes capturing login details or monitoring user input.
- ✗
Adware
Why it's wrong here
Adware injects or redirects advertising and may track browsing, but performs no file encryption or ransom demand. It is tempting because it is unwanted and often bundled with other payloads, and it would be the correct answer where the scenario describes forced advertisements or browser hijacking.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.