nerdexam
CompTIA

SY0-501 · Question #562

A security administrator is reviewing the following network capture: Which of the following malware is MOST likely to generate the above information?

The correct answer is A. Keylogger. A network capture showing information being generated is most indicative of a keylogger, which captures keystrokes and transmits them over the network.

Submitted by ahmad_uae· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

A security administrator is reviewing the following network capture:

Which of the following malware is MOST likely to generate the above information?

Options

  • AKeylogger
  • BRansomware
  • CLogic bomb
  • DAdware

How the community answered

(58 responses)
  • A
    76% (44)
  • B
    14% (8)
  • C
    3% (2)
  • D
    7% (4)

Why each option

A network capture showing information being generated is most indicative of a keylogger, which captures keystrokes and transmits them over the network.

AKeyloggerCorrect

Keyloggers are a type of surveillance software designed to record user keystrokes and other input without their knowledge. This captured 'information' (keystrokes, passwords, sensitive data) is then typically exfiltrated over the network to an attacker, making it visible in a network capture.

BRansomware
CLogic bomb
DAdware

Adware primarily aims to display unwanted advertisements, redirect web traffic, and gather marketing data, but it does not typically focus on the covert exfiltration of captured keystrokes or other specific 'information' in the same manner as a keylogger.

Concept tested: Malware types and their network behavior

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/malware-types?view=o365-worldwide

Topics

#keylogger#malware analysis#network capture#traffic analysis

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice