Courseiva
easyMultiple Select

ISC2 CC Practice Question: Which TWO of the following are common indicators…

Which TWO of the following are common indicators of a ransomware attack?

⚠ Common exam trap

ISC2 often tests the distinction between ransomware indicators and general malware or intrusion indicators, so candidates mistakenly associate user account creation (Option A) with ransomware when it is actually a lateral movement technique, not a direct ransomware artifact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Files with .encrypted extension.

Option D is correct because ransomware typically encrypts victim files and appends a distinctive extension such as .encrypted (or .locked, .crypto, etc.) to each affected file, making it one of the most reliable file-system indicators of an active infection. Option E is correct because most ransomware families drop a ransom note — often in the form of a text file, HTML page, or a full-screen desktop wallpaper/message — demanding payment in cryptocurrency in exchange for the decryption key. Option A is not a typical ransomware indicator; new user accounts are more commonly associated with persistence or privilege-escalation techniques used by other malware or intruders. Option B is incorrect because ransomware encryption and file I/O typically cause elevated CPU/disk usage and degraded performance, not improved system performance. Option C is incorrect because ransomware often increases network traffic (e.g., C2 communication, key exchange, exfiltration) rather than causing a sudden decrease.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    New user accounts created.

    Why it's wrong here

    Ransomware typically encrypts files and drops ransom notes; new account creation is not a characteristic indicator, being associated with persistence or privilege escalation instead. It is tempting because attackers do sometimes create accounts, and it would be correct for a suspected credential-compromise or insider-threat investigation.

  • ✗

    Elevated system performance.

    Why it's wrong here

    Ransomware encryption and file operations consume CPU and disk, degrading performance rather than elevating it, so this contradicts the expected symptom. It is tempting because performance monitoring is a valid detection input, and elevated throughput would be correct for cryptomining or data-exfiltration activity instead.

  • ✗

    Sudden decrease in network traffic.

    Why it's wrong here

    Ransomware typically increases network traffic through encryption, exfiltration or command-and-control beaconing, so a sudden decrease contradicts the expected pattern. It is tempting because outages or containment can reduce traffic, but that reflects disruption after the fact rather than the attack's characteristic indicators.

  • ✓

    Files with .encrypted extension.

    Why this is correct

    Ransomware encrypts victim files and commonly appends a distinctive extension such as .encrypted, making mass file renaming a reliable host-based indicator. It reflects the encryption stage of the attack rather than mere delivery or lateral movement.

  • ✓

    Ransom note displayed on screen.

    Why this is correct

    A visible ransom note is a hallmark symptom of active ransomware encryption, directly satisfying the stem's request for common indicators. It signals files have been locked and payment demanded, distinguishing ransomware from other malware that hides its presence.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.