Malware Attack Indicators for Security+
Short answer
Malware indicators are observable behaviors. Ransomware indicators include sudden file encryption, changed file extensions, ransom notes, inaccessible shared files, disabled backups, unusual encryption activity, and payment instructions. The key clue is coercive locking or encryption, not merely malware infection.
Why it appears on the exam
SY0-701 2.4: Recognize likely indicators of ransomware, Trojans, worms, spyware, viruses, keyloggers, logic bombs, rootkits, and related malware.
Key concepts
Concept 1
How Malware Attack Indicators works
Malware indicators are observable behaviors. Ransomware indicators include sudden file encryption, changed file extensions, ransom notes, inaccessible shared files, disabled backups, unusual encryption activity, and payment instructions. The key clue is coercive locking or encryption, not merely malware infection.
Example
Multiple file shares become unreadable and each directory contains payment instructions. The likely malware activity is ransomware.
Concept 2
Common confusion
Learners often confuse worms and viruses. A worm self-propagates across systems or networks. A virus attaches to a host file or program and spreads when that host runs. Learners also confuse spyware and keylogger; keylogger is keystroke-specific, while spyware is broader collection.
Example
A user installs a fake PDF converter and the workstation starts beaconing to an unknown host. The likely malware type is Trojan.
Concept 3
What to recognize
Match observed behavior to ransomware, Trojan, worm, spyware, bloatware, virus, keylogger, logic bomb, or rootkit; Distinguish malware behavior from vulnerability class and mitigation choice; Recognize that one incident can include multiple malware behaviors but the best answer follows the dominant clue; Unfair targets: requiring malware family names, hash analysis, disassembly, sandbox report fields, removal steps, or endpoint detection and response (EDR) product syntax.
Example
Many internal hosts begin scanning each other shortly after one system is infected. The behavior suggests a worm.
Sample questions
Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.
Q1.On the exam, this detail appears: Multiple file shares become unreadable and each directory contains payment instructions. The likely malware activity is ransomware. Which answer matches it?
Q2.A Security+ scenario centers on Malware Attack Indicators. Which answer is the closest lesson match?
Q3.A Security+ scenario about Malware Attack Indicators looks similar to a nearby topic. What should you do before choosing an answer?
Practice this lesson in Cultiv8
The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.
Continue in Cultiv8