Core Malware Families and Their Behaviors for A+
Short answer
Provide a one-idea-per-term description that ties each family to the observable impact a technician sees: propagation (virus), disguise/access (Trojan), data hostage (ransomware), data collection (spyware/keylogger), and resource theft (cryptominer). The technician should map symptoms (high CPU, ransom note, unusual network traffic, shared-file infection) to these families.
Why it appears on the exam
- Given a short scenario (ransom note + encrypted files), identify ransomware. - Match symptoms (high CPU after visiting website) to cryptominer. - Identify that a program installed by the user that opens a remote backdoor is likely a Trojan.
Key concepts
Concept 1
Required terms
Trojan: Malicious code disguised as legitimate software or bundled with legitimate software that provides an attacker access or unwanted functionality when executed. Virus: Malware that attaches to executable files or documents and replicates when the host is run; often spreads via infected files or removable media. Ransomware: Malware that encrypts user data or locks system access and demands payment in exchange for decryption or restoration. Spyware: Software that covertly collects information about a user's activities and transmits it to a third party without proper consent.
Example
Trojan: User runs a cracked installer and later reports remote desktop access appearing.
Concept 2
How Core Malware Families and Their Behaviors works
Provide a one-idea-per-term description that ties each family to the observable impact a technician sees: propagation (virus), disguise/access (Trojan), data hostage (ransomware), data collection (spyware/keylogger), and resource theft (cryptominer). The technician should map symptoms (high CPU, ransom note, unusual network traffic, shared-file infection) to these families.
Example
Virus: Several machines using the same USB drive start failing to open certain executables.
Concept 3
Common confusion
- Using 'virus' as a catchall term for all malware. Emphasize replication behavior for viruses. - Confusing Trojans with worms; Trojans need a user to install them, worms self-propagate. - Mistaking high CPU from legitimate apps for cryptominer activity; use correlation with timing and recent installs.
Example
Ransomware: User finds files renamed and a ransom note on the desktop demanding payment.
Concept 4
Core 2 (220-1202) question cues
Given a short scenario (ransom note + encrypted files), identify ransomware; Match symptoms (high CPU after visiting website) to cryptominer; Identify that a program installed by the user that opens a remote backdoor is likely a Trojan.
Example
Spyware/Keylogger: Bank account accessed despite strong passwords; logs indicate background process capturing input.
Sample questions
Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.
Q1.A technician is troubleshooting this situation: Trojan: User runs a cracked installer and later reports remote desktop access appearing. What should they identify?
Q2.A support ticket includes this clue: Virus: Several machines using the same USB drive start failing to open certain executables. Which concept is being tested?
Q3.An A+ support scenario describes this situation: Ransomware: User finds files renamed and a ransom note on the desktop demanding payment. Which answer fits best?
Practice this lesson in Cultiv8
The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.
Continue in Cultiv8