Courseiva
easyMultiple Choice

SSCP Practice Question: That their computer is displaying a fake…

A user reports that their computer is displaying a fake antivirus warning that demands payment. This is an example of which type of attack?

⚠ Common exam trap

A common mix-up: candidates confuse scareware with ransomware because both demand payment, but scareware does not encrypt files or lock the system—it only displays a fake warning, which is a key distinction tested on the SSCP exam.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scareware

Scareware is a type of malware that uses social engineering to trick users into believing their system is infected, then demands payment for a fake removal tool. The fake antivirus warning is a classic scareware tactic, as it creates urgency and fear to coerce payment, unlike ransomware which encrypts files and demands a ransom for decryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Social engineering

    Why it's wrong here

    Social engineering is the broader category covering manipulation of people; the question asks for the specific attack type, which is scareware. Social engineering is tempting because scareware does manipulate the user through fear, and would be correct if the question asked for the general classification rather than the precise attack name.

  • ✗

    Ransomware

    Why it's wrong here

    Ransomware encrypts files and demands payment for the decryption key; a fake antivirus pop-up demanding payment is scareware, a social-engineering technique. Ransomware is tempting because both demand payment, but ransomware requires actual file encryption, whereas this scenario shows only a deceptive warning with no encryption.

  • ✗

    Phishing

    Why it's wrong here

    Phishing delivers a fraudulent message, typically by email, to trick recipients into revealing credentials or clicking links; this scenario involves a local fake antivirus pop-up, which is scareware. Phishing is tempting because both are social-engineering attacks, but phishing requires an external delivery vector absent here.

  • ✓

    Scareware

    Why this is correct

    Scareware fabricates antivirus alerts demanding payment, directly matching the stem's fake warning. Unlike ransomware, which encrypts files, scareware relies on psychological manipulation alone, with no encryption or data theft. This social-engineering tactic satisfies the scenario's defining constraint: a fraudulent security prompt extorting money through fear.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.