220-1102 Question 259
Single answerInformationalA help desk technician receives a report that a user's Windows PC displays a pop-up claiming, "Your computer is infected. Call support now," but the user can still open files and applications normally. The technician finds no signs of encrypted files, disabled services, or system instability. Which type of malware or malicious behavior is MOST likely involved?
- A
Ransomware
- B
Scareware
- C
Rootkit
- D
Keylogger
Show answer and explanation
Correct answer: B
Explanation
The best answer is scareware. On A+ Core 2, informational malware identification includes recognizing common behavioral patterns. Scareware relies on social engineering by presenting fake alerts that attempt to frighten users into taking harmful actions, such as paying for bogus cleanup tools or contacting fraudulent support. By contrast, ransomware generally restricts access through encryption or lockout, rootkits focus on stealth and persistence, and keyloggers silently capture input. Security best practices from major vendors such as Microsoft and CISA emphasize verifying alerts through trusted security tools, avoiding interaction with suspicious pop-ups, and educating users to report these incidents rather than calling the number shown in the message.
- A. Incorrect.
Ransomware is incorrect because ransomware typically blocks access to data or systems, often by encrypting files or locking the screen until a payment is made. In this scenario, the user can still access files and applications normally, which does not match the usual behavior of ransomware.
- B. Correct.
Scareware is correct because scareware commonly displays alarming but misleading messages claiming the system is infected or at risk in order to pressure the user into calling fake support, purchasing unnecessary software, or granting remote access. The fake infection warning with normal system functionality is a classic scareware indicator.
- C. Incorrect.
Rootkit is incorrect because a rootkit is designed to hide malicious activity and maintain privileged access while avoiding detection. It does not typically present obvious warning pop-ups to the user. Someone might choose this option because rootkits are serious malware, but the visible social engineering component here points elsewhere.
- D. Incorrect.
Keylogger is incorrect because a keylogger secretly records keystrokes to capture credentials or sensitive information. It is usually intended to remain hidden and would not normally announce itself with a fake infection message. This option may tempt candidates who associate any malware incident with credential theft, but the described symptom is primarily a scare tactic.