Security+ Lesson

Malware Attack Indicators for Security+

Last updated: 6/10/2026

Short answer

Malware indicators are observable behaviors. Ransomware indicators include sudden file encryption, changed file extensions, ransom notes, inaccessible shared files, disabled backups, unusual encryption activity, and payment instructions. The key clue is coercive locking or encryption, not merely malware infection.

Why it appears on the exam

SY0-701 2.4: Recognize likely indicators of ransomware, Trojans, worms, spyware, viruses, keyloggers, logic bombs, rootkits, and related malware.

Key concepts

Concept 1

How Malware Attack Indicators works

Malware indicators are observable behaviors. Ransomware indicators include sudden file encryption, changed file extensions, ransom notes, inaccessible shared files, disabled backups, unusual encryption activity, and payment instructions. The key clue is coercive locking or encryption, not merely malware infection.

Example

Multiple file shares become unreadable and each directory contains payment instructions. The likely malware activity is ransomware.

Concept 2

Common confusion

Learners often confuse worms and viruses. A worm self-propagates across systems or networks. A virus attaches to a host file or program and spreads when that host runs. Learners also confuse spyware and keylogger; keylogger is keystroke-specific, while spyware is broader collection.

Example

A user installs a fake PDF converter and the workstation starts beaconing to an unknown host. The likely malware type is Trojan.

Concept 3

What to recognize

Match observed behavior to ransomware, Trojan, worm, spyware, bloatware, virus, keylogger, logic bomb, or rootkit; Distinguish malware behavior from vulnerability class and mitigation choice; Recognize that one incident can include multiple malware behaviors but the best answer follows the dominant clue; Unfair targets: requiring malware family names, hash analysis, disassembly, sandbox report fields, removal steps, or endpoint detection and response (EDR) product syntax.

Example

Many internal hosts begin scanning each other shortly after one system is infected. The behavior suggests a worm.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.On the exam, this detail appears: Multiple file shares become unreadable and each directory contains payment instructions. The likely malware activity is ransomware. Which answer matches it?

Q2.A Security+ scenario centers on Malware Attack Indicators. Which answer is the closest lesson match?

Q3.A Security+ scenario about Malware Attack Indicators looks similar to a nearby topic. What should you do before choosing an answer?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8