nerdexam
CompTIA

SY0-501 · Question #515

Ann, a customer, is reporting that several important files are missing from her workstation. She recently received communication from an unknown party who is requesting funds to restore the files…

The correct answer is A. Ransomware. Ann's workstation files are missing, and an unknown party is demanding funds for their restoration, which are classic indicators of a ransomware attack.

Submitted by the_admin· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

Ann, a customer, is reporting that several important files are missing from her workstation. She recently received communication from an unknown party who is requesting funds to restore the files. Which of the following attacks has occurred?

Options

  • ARansomware
  • BKeylogger
  • CBuffer overflow
  • DRootkit

How the community answered

(46 responses)
  • A
    72% (33)
  • B
    4% (2)
  • C
    15% (7)
  • D
    9% (4)

Why each option

Ann's workstation files are missing, and an unknown party is demanding funds for their restoration, which are classic indicators of a ransomware attack.

ARansomwareCorrect

Ransomware is a type of malicious software that encrypts a victim's files, making them inaccessible, and then demands a payment, or 'ransom,' to restore access to the data, typically by providing a decryption key. The scenario directly describes files being held hostage with a demand for funds to restore them, which is the defining characteristic of a ransomware attack.

BKeylogger

A keylogger is designed to record keystrokes made on a keyboard, not to encrypt files or demand a ransom for their restoration.

CBuffer overflow

A buffer overflow is a type of software vulnerability where a program attempts to write data beyond the boundaries of a fixed-size buffer, often leading to system crashes or arbitrary code execution, but not directly to file encryption for ransom.

DRootkit

A rootkit is a collection of software tools designed to enable persistent, surreptitious access to a computer while actively hiding its presence and that of other malware, rather than directly encrypting user files and demanding payment.

Concept tested: Identifying ransomware attack characteristics

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/malware-encyclopedia/ransomware

Topics

#ransomware#malware#extortion#file encryption

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice