ISC2 CC Security Operations Practice Question
An employee reports that their laptop suddenly displays a message demanding payment in cryptocurrency to restore access to files, and the files now have an unfamiliar extension. The employee has not clicked any links recently. Which type of malware is MOST likely responsible?
⚠ Common exam trap
The trap here is assuming ransomware always requires a recent link click, which overlooks exploit-based and service-based delivery methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ransomware
The combination of encrypted files, altered extensions, and a cryptocurrency ransom demand is the classic signature of ransomware. Delivery does not require a recent link click, since exploits, malicious attachments, and exposed services are common vectors. Recognizing these indicators lets responders isolate the host quickly, preserve evidence, and avoid paying, while restoring from offline backups if available.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A logic bomb
Why it's wrong here
A logic bomb is malicious code that triggers when a specific condition is met, such as a date or the removal of an employee record. It does not inherently encrypt files or display cryptocurrency payment instructions. While destructive, its behavior differs from the observable ransom note and renamed files, so it does not best explain the reported incident.
- ✗
A keylogger
Why it's wrong here
A keylogger covertly records keystrokes to capture credentials and other sensitive input, operating quietly in the background. It does not encrypt files, rename them, or present a ransom demand to the user. Since the reported symptoms are file inaccessibility and a payment message, a keylogger is not consistent with this scenario's evidence.
- ✗
A rootkit
Why it's wrong here
A rootkit hides itself and maintains persistent privileged access while concealing its presence from the operating system. It does not typically display payment demands or rename user files with unfamiliar extensions. The visible ransom note and encrypted files point to a different malware category, so a rootkit does not explain the symptoms the employee reported here.
- ✓
Ransomware
Why this is correct
Ransomware encrypts files, often appends unfamiliar extensions, and displays a ransom demand for decryption keys, which matches every symptom described. The cryptocurrency payment demand is a hallmark of this malware class. Even without a recent link click, delivery can occur through exploits, malicious documents, or compromised remote services, making ransomware the most likely culprit.
Go deeper
Related to this question
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.