SY0-701 exam dumps

SY0-701 practice question 110 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 110

Single answerMalware attacks: Ransomware , Trojan , Worm , Spyware , Bloatware , Virus , Keylogger , Logic bomb , Rootkit

A security analyst is investigating several Windows workstations after users reported slow performance and unexpected browser pop-ups. Endpoint protection shows no known ransomware activity, but one finance employee also reports that passwords typed into internal applications may have been exposed. On one affected system, the analyst finds a recently installed 'free PDF converter' that appears legitimate, but it created hidden persistence mechanisms, captures keystrokes, and sends data to an external server. Which type of malware best matches this scenario?

  1. A

    Trojan

  2. B

    Worm

  3. C

    Logic bomb

  4. D

    Rootkit

  5. E

    Bloatware

Show answer and explanation

Correct answer: A

Explanation

The best answer is Trojan because the key indicator is deceptive delivery: malware presented as a legitimate application that convinces a user to install it. The additional behaviors described, such as capturing keystrokes and sending data externally, align with spyware or a keylogger payload delivered by the Trojan. Security+ expects candidates to distinguish malware by how it operates and spreads, not just by one symptom. A worm spreads autonomously, a logic bomb waits for a trigger, a rootkit hides malicious activity, and bloatware is typically nonmalicious unwanted software. Best practices from sources such as CISA and NIST emphasize user awareness training, application allowlisting, endpoint detection and response, least privilege, and software restriction policies to reduce successful Trojan-based infections.

  • A. Correct.

    Correct. A Trojan is malware disguised as legitimate software to trick users into installing it. In this scenario, the 'free PDF converter' appears benign but actually installs malicious functionality, including keystroke capture and data exfiltration. Trojans commonly deliver additional payloads such as spyware or keyloggers while relying on social engineering rather than self-replication.

  • B. Incorrect.

    Incorrect. A worm is designed to self-replicate and spread automatically across systems or networks without requiring a user to install what appears to be legitimate software. The scenario focuses on deceptive installation through a fake useful application, which is more characteristic of a Trojan than a worm.

  • C. Incorrect.

    Incorrect. A logic bomb is malicious code that activates when a specific condition is met, such as a date, time, or user action. The scenario does not describe a trigger-based payload waiting for a condition; instead, it describes an actively running malicious program disguised as legitimate software and immediately performing surveillance and exfiltration.

  • D. Incorrect.

    Incorrect. A rootkit is a stealth mechanism used to hide malware or attacker activity, often by modifying the operating system or operating at a privileged level. Although the malware in this scenario uses hidden persistence, the primary identifying feature is that it masqueraded as legitimate software to gain installation. A rootkit could be part of the attack, but it is not the best overall classification.

  • E. Incorrect.

    Incorrect. Bloatware refers to unwanted or unnecessary software that consumes system resources, often preinstalled by vendors or bundled with applications. While bloatware can slow systems, it does not typically include malicious behavior such as keylogging and exfiltrating credentials. Choosing this option would confuse nuisance software with malware.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam