easyMultiple SelectObjective-mapped
ISC2 CC Practice Question: Which TWO of the following are common indicators…
Which TWO of the following are common indicators of a ransomware attack?
⚠ Common exam trap
ISC2 often tests the distinction between ransomware indicators and general malware or intrusion indicators, so candidates mistakenly associate user account creation (Option A) with ransomware when it is actually a lateral movement technique, not a direct ransomware artifact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Files with .encrypted extension.
Options D and E are correct because ransomware typically encrypts files and appends a new extension such as .encrypted (Option D) and displays a ransom note demanding payment for decryption (Option E). These are two of the most common indicators of a ransomware attack. In contrast, new user accounts (Option A) are not typically associated with ransomware, elevated system performance (Option B) is the opposite of what occurs, and a sudden decrease in network traffic (Option C) may indicate other issues but is not a direct indicator of ransomware.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
New user accounts created.
Why it's wrong here
Ransomware typically does not create new user accounts.
- ✗
Elevated system performance.
Why it's wrong here
Ransomware may cause performance degradation, not elevation.
- ✗
Sudden decrease in network traffic.
Why it's wrong here
Network traffic may increase due to encryption, not decrease.
- ✓
Files with .encrypted extension.
Why this is correct
Encrypted file extensions are a common sign of ransomware.
- ✓
Ransom note displayed on screen.
Why this is correct
Ransom notes are a hallmark of ransomware.
Go deeper
Related to this question
Learn chapter
Network Security Foundations
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Decryption
Decryption is the process of converting encrypted or scrambled data back into its original, readable form using a specific key or method.
About these practice questions
Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.