SY0-701 exam dumps

SY0-701 practice question 108 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 108

Single answer2.4 Given a scenario, analyze indicators of malicious activity.

A security analyst notices that a file server is generating a much higher volume of outbound SMB traffic than normal to multiple internal workstations. At the same time, users report that shared documents now have a new file extension and cannot be opened. The server's CPU and disk utilization are also unusually high, and the SIEM shows many rapid file rename events. Which indicator of malicious activity is MOST strongly supported by this scenario?

  1. A

    A ransomware infection is encrypting files and attempting to spread across the network

  2. B

    A rogue access point is redirecting wireless users to a captive portal

  3. C

    A logic bomb has triggered to delete system logs at a preset time

  4. D

    A cryptojacking malware infection is only consuming local CPU resources for mining

Show answer and explanation

Correct answer: A

Explanation

The strongest indicator here is ransomware. Security professionals are expected to recognize patterns rather than rely on a single artifact. Common ransomware indicators include sudden file extension changes, inability to open files, mass file rename or write operations, and spikes in CPU/disk usage caused by encryption. Increased SMB traffic can indicate the malware is targeting network shares or moving laterally to additional hosts. These are practical indicators of malicious activity that defenders often validate through SIEM alerts, endpoint telemetry, and file server auditing. This aligns with common guidance from organizations such as CISA and NIST on identifying ransomware activity through anomalous file access patterns, resource utilization spikes, and unauthorized encryption behavior.

  • A. Correct.

    Correct. Multiple classic indicators of ransomware are present: files becoming inaccessible, new file extensions, rapid file rename activity, and abnormal CPU/disk usage during encryption. The increased outbound SMB traffic to many internal workstations also suggests lateral movement or propagation through shared folders and administrative shares. This combination strongly points to ransomware rather than a benign file operation.

  • B. Incorrect.

    Incorrect. A rogue access point typically presents indicators such as unexpected SSIDs, wireless association anomalies, certificate warnings, or users being redirected through suspicious web login pages. The scenario focuses on SMB traffic, file renaming, inaccessible documents, and server resource spikes, which are not primary indicators of a wireless redirection attack.

  • C. Incorrect.

    Incorrect. A logic bomb is malicious code triggered by a condition or time-based event, but the scenario does not describe selective deletion or a trigger event tied to log removal. Instead, the observable signs are mass file modification, extension changes, and heavy SMB activity, which align much more closely with ransomware behavior.

  • D. Incorrect.

    Incorrect. Cryptojacking commonly causes high CPU usage and sometimes degraded system performance, but it does not typically rename files, make documents inaccessible, or generate widespread SMB-based file modification activity. Someone might choose this option because of the high CPU utilization, but the file encryption indicators make cryptojacking unlikely.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam