SY0-701 exam dumps

SY0-701 practice question 111 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 111

Single answerMalware attacks: Ransomware , Trojan , Worm , Spyware , Bloatware , Virus , Keylogger , Logic bomb , Rootkit

A security administrator is investigating a workstation that began performing poorly after a user installed a free browser add-on from an untrusted website. The user reports constant pop-up ads, unexpected browser redirects, and a large number of new preinstalled utilities that consume CPU and memory. Antivirus scans do not show file encryption or self-replication to other hosts. Which malware category best explains the primary issue on this workstation?

  1. A

    Spyware

  2. B

    Worm

  3. C

    Ransomware

  4. D

    Logic bomb

  5. E

    Bloatware

Show answer and explanation

Correct answer: A

Explanation

The best answer is spyware because the most significant indicators are browser redirects, intrusive pop-ups, and likely unauthorized tracking following the installation of an untrusted add-on. Security+ candidates should distinguish malware types by behavior: ransomware encrypts data for extortion, worms self-propagate, logic bombs trigger on conditions, and bloatware mainly wastes system resources without necessarily spying on users. In practice, malicious browser extensions often combine adware-like symptoms with spyware capabilities, making user education, application allowlisting, browser extension controls, and endpoint detection important mitigations. This aligns with common guidance from CISA, NIST malware defense practices, and standard endpoint security best practices emphasizing least privilege, trusted software sources, and continuous monitoring.

  • A. Correct.

    Correct. Spyware is designed to collect information about a user or system, often without consent, and is commonly associated with browser tracking, intrusive advertisements, redirects, and monitoring of user activity. In real-world cases, malicious browser add-ons frequently behave like spyware or adware by harvesting browsing data and altering browser behavior. The scenario points to unauthorized monitoring and browser manipulation rather than encryption or autonomous spreading.

  • B. Incorrect.

    Incorrect. A worm is malware that self-replicates and spreads across systems or networks without requiring a host file. The scenario specifically notes there is no sign of self-replication to other hosts, which argues against a worm. Someone might choose this option because worms can degrade performance, but the browser-specific symptoms and lack of lateral spread make it a poor fit.

  • C. Incorrect.

    Incorrect. Ransomware typically encrypts files or systems and demands payment for restoration. The scenario explicitly states there is no file encryption, so this is not the best answer. A candidate might be tempted by the severe system impact, but the hallmark behavior of ransomware is extortion through denial of access, which is absent here.

  • D. Incorrect.

    Incorrect. A logic bomb is malicious code triggered by a specific condition or event, such as a date, user action, or account deletion. While it may cause damage or disruption, it does not usually manifest as persistent pop-ups, browser redirects, and ongoing tracking behavior. This distractor targets the misconception that any hidden malicious function is a logic bomb.

  • E. Incorrect.

    Incorrect. Bloatware refers to unnecessary software that consumes resources, often preinstalled by a vendor or bundled with other applications. Although the new utilities consuming CPU and memory resemble bloatware, bloatware alone does not best explain the pop-up ads, browser redirects, and likely data collection. Those symptoms are more consistent with spyware. This is a plausible distractor because the scenario includes resource-heavy unwanted software, but the primary issue is covert monitoring and browser manipulation.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam