Courseiva
easyMultiple Select

SSCP Practice Question: Which TWO of the following are common indicators…

Which TWO of the following are common indicators of a ransomware attack?

⚠ Common exam trap

SSCP often tests the distinction between generic malware indicators (like unusual outbound traffic) and ransomware-specific artifacts (file extensions and ransom notes), causing candidates to select broader but incorrect options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Files with .encrypted extension appearing in directories.

Option A is correct because ransomware typically renames victim files with a distinctive extension (e.g., .encrypted, .locked, .crypto) after encrypting them, so the sudden appearance of files with an .encrypted extension in directories is a classic indicator of an active ransomware attack. Option D is correct because most ransomware families drop a ransom note (often named README.txt, DECRYPT_INSTRUCTIONS.txt, or similar) into every affected folder to instruct the victim on how to pay for the decryption key, making its presence a strong forensic indicator. Option B is not the best choice here because while unusual outbound traffic can indicate malware or C2 communication, it is a generic indicator of many compromises rather than a specific hallmark of ransomware. Option C is incorrect because ransomware does not typically reduce network latency; if anything, mass encryption and file operations tend to degrade system and network performance. Option E is incorrect because failed login attempts point to brute-force or credential-stuffing activity, which is an initial access technique rather than a ransomware-specific indicator.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Files with .encrypted extension appearing in directories.

    Why this is correct

    Ransomware encrypts victim files and typically renames them with a distinctive appended extension, so novel extensions such as .encrypted appearing en masse indicate encryption in progress. This is a direct file-system artefact of the attack, satisfying the stem's indicator requirement.

  • ✗

    Unusual outbound network traffic to unknown IPs.

    Why it's wrong here

    This could indicate many types of malware, not solely ransomware.

  • ✗

    Decreased network latency.

    Why it's wrong here

    Decreased latency is not a ransomware indicator; encryption, file locking and mass storage activity typically degrade performance and increase latency. It is tempting because latency changes are measurable network symptoms, and would be correct for diagnosing congestion or routing problems rather than malicious encryption.

  • ✓

    A ransom note text file in each affected folder.

    Why this is correct

    Ransomware operators leave instructions demanding payment, commonly as a text file dropped into every traversed directory so victims find it. Its appearance across multiple folders evidences automated, widespread encryption activity, satisfying the stem's indicator requirement.

  • ✗

    System log entries showing failed login attempts.

    Why it's wrong here

    Failed login entries indicate credential-guessing or brute-force attempts, which precede intrusion rather than the encryption and extortion behaviour ransomware exhibits. It is tempting because failed logins are a genuine security indicator, and would be correct for detecting password attacks or account compromise attempts.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.