Security+ SY0-701 · Domain 2
Domain 2: Threats, Vulnerabilities & Mitigations
Why This Domain Matters
Domain 2 is the largest pure-study domain on the exam (22%) and the one a SOC analyst draws on every single shift: it's the taxonomy behind every endpoint alert, every phishing report, and every "why did this account lock out" ticket.
Where Domain 1 gives the vocabulary, Domain 2 gives the actual catalogue of things that go wrong — who does it (2.1), how they get in (2.2), what they exploit (2.3), what it looks like when it happens (2.4), and what to do about it (2.5).
Read it as one continuous story: actor → vector → vulnerability → indicator → mitigation.
Objective-by-Objective Breakdown
2.1 Threat Actors & Motivations
The attack chain — actor, vector, vulnerability, indicator, mitigation, in order
The exam separates who (actor type) from why (motivation) from attributes (how capable/resourced they are) — a stem can test any of the three independently.
Actor types:
- nation-state: state-sponsored, highest resources/sophistication, often long-dwell espionage
- unskilled attacker: a.k.a. "script kiddie" — low skill, uses off-the-shelf tools
- hacktivist: ideologically motivated, disruption/defacement over profit
- insider threat: current/former employee or contractor abusing legitimate access
- organized crime: financially motivated, structured, persistent
- shadow IT: not a malicious actor per se — employees standing up unsanctioned systems/apps, creating risk through negligence rather than intent
Attributes:
- internal vs. external: is the actor inside or outside the organisation's trust boundary — an insider threat is internal by definition
- level of resources/funding: nation-states >> organized crime >> hacktivists >> unskilled attackers, as a rough exam ranking
- level of sophistication/capability: correlates with resources but is tested separately — a well-funded actor can still buy unsophisticated tools
Motivations:
- data exfiltration
- espionage: nation-state hallmark
- service disruption
- blackmail
- financial gain: organized crime hallmark
- philosophical/political beliefs: hacktivist hallmark
- ethical: e.g. a bug-bounty researcher or "white hat" disclosure motive
- revenge: common insider-threat driver
- disruption/chaos
- war: nation-state, cyberwarfare context
2.2 Threat Vectors & Attack Surfaces
A vector is the specific path an attack travels; the attack surface is the sum of everywhere it could enter. The exam groups vectors into technical categories and a separate human/social-engineering category.
Technical vectors:
- message-based: email, SMS, instant messaging — still the dominant delivery method
- image-based: malicious code or payloads embedded in image files
- file-based: malicious documents/attachments
- voice call: vishing delivery
- removable device: USB drops
- vulnerable software — split into client-based (an installed application with an exploitable flaw, e.g. an outdated PDF reader) vs. agentless (a vulnerable service reachable without any installed client, e.g. an exposed web app)
- unsupported systems/applications: end-of-support software with no patches
- unsecure networks: wireless, wired, Bluetooth — each with its own weaknesses
- open service ports: unnecessarily exposed listening services
- default credentials: vendor defaults never changed
- supply chain: risk introduced via MSPs, vendors, and suppliers — this cuts both ways depending on which side of the relationship an organization is on
Human vectors / social engineering — the exam's favourite exploitable "vulnerability" is always the human:
- Phishing — broad, email-based deception to harvest credentials or deliver malware.
- Vishing — voice-call phishing.
- Smishing — SMS-based phishing.
- Misinformation/disinformation — false information spread (misinformation = spread without intent to deceive; disinformation = deliberately fabricated and spread to deceive — see Confusables).
- Impersonation — pretending to be a trusted person to manipulate a target.
- Business email compromise (BEC) — compromising or spoofing a business email account (often executive) to induce fraudulent transfers or data disclosure.
- Pretexting — inventing a fabricated scenario/identity to extract information (often the mechanism underneath impersonation or vishing).
- Watering hole — compromising a website the target population is known to visit, waiting for victims to come to the trap rather than pushing the attack out.
- Brand impersonation — mimicking a trusted brand's look/domain/communications.
- Typosquatting — registering a misspelled or lookalike domain to catch mistyped URLs.
2.3 Vulnerability Types
Vulnerabilities are grouped by where the weakness lives.
Application:
- memory injection: malicious code injected into a running process's memory space
- buffer overflow: input exceeds allocated memory, overwriting adjacent memory — can lead to code execution
- race conditions — specifically TOCTOU: time-of-check to time-of-use: a resource's state changes between when it's checked and when it's used, exploitable in that window
- malicious update: a legitimate-seeming update channel used to deliver malicious code — a supply-chain-adjacent risk
OS-based: unpatched or misconfigured operating systems exposing known flaws.
Web-based: SQL injection (unsanitised input alters a backend database query, can read/modify/delete data it shouldn't), cross-site scripting (XSS) (malicious script injected into a trusted web page, executed in the victim's browser context — see Confusables for the CSRF distinction).
Hardware:
- firmware: low-level device software vulnerabilities, e.g. router/BIOS firmware never updated
- end-of-life: vendor no longer sells/supports it
- legacy: outdated but still in use, often because replacement is costly/disruptive
Virtualization: VM escape (code in a guest VM breaks out to affect the host or other VMs — a hypervisor-boundary failure), resource reuse (data remnants from one VM/tenant improperly exposed to the next tenant reusing the same physical resource).
Cloud-specific:
- vulnerabilities arising from shared-responsibility gaps
- misconfigured storage/identity
- multi-tenant exposure unique to cloud platforms
Supply chain: service provider, hardware provider, software provider — risk inherited from any third party in the delivery chain (distinct from 2.2's supply-chain vector: 2.3 is the vulnerability that exists because of that dependency).
Cryptographic: weak algorithms, poor key management, or implementation flaws that undermine confidentiality/integrity guarantees.
Misconfiguration: default settings, excessive permissions, or unhardened services left as-is — the most common and most preventable vulnerability class.
Mobile device: side loading (installing apps from outside the official app store, bypassing vetting), jailbreaking (removing OS-imposed restrictions, eliminating vendor security controls).
Zero-day: a vulnerability unknown to the vendor (no patch exists) — distinct from an unpatched known vulnerability, which just hasn't been remediated yet.
2.4 Indicators of Malicious Activity
This objective is a direct map to what actually populates your Defender for Endpoint alert queue.
Malware attacks:
- ransomware: encrypts data for extortion
- trojan: malicious code disguised as legitimate software
- worm: self-replicates and spreads across a network without user action — the self-propagation is the defining trait
- spyware: covertly monitors/collects user activity
- bloatware: unwanted pre-installed software — not necessarily malicious, but expands attack surface
- virus: malicious code that requires a host file/user action to execute and spread — this is what separates it from a worm
- keylogger: captures keystrokes
- logic bomb: dormant code that triggers on a specific condition/date
- rootkit: embeds at a privileged level to hide its own and other malware's presence
Physical attacks:
- brute force: repeated physical attempts, e.g. lock picking, or repeated login attempts — context-dependent
- RFID cloning: duplicating a badge/access card's signal
- environmental: attacks or failures via HVAC, power, fire suppression manipulation
Network attacks: DDoS — amplified (a small request to a third-party service generates a disproportionately large response directed at the victim, e.g.
DNS amplification) vs. reflected (the attacker spoofs the victim's source IP so replies are reflected onto the victim — amplification and reflection are usually combined, but the exam can test either property alone; see Confusables).
DNS attacks (poisoning, hijacking — corrupting or redirecting the name-to-address lookup so victims are sent to malicious infrastructure while typing the correct address). Wireless attacks (rogue APs, deauthentication).
On-path (attacker positions between two communicating parties to intercept/alter traffic — the modern term for "man-in-the-middle"). Credential replay (captured valid credentials/tokens reused to gain access without cracking them). Malicious code (generic execution of attacker-supplied code across any of the above).
Application attacks:
- injection: SQLi and similar — untrusted input executed as commands
- buffer overflow: as in 2.3, but here as an observed attack rather than the underlying flaw
- replay: a captured legitimate transaction/session resent to repeat its effect
- privilege escalation: an attacker or process gains rights beyond what was granted — vertical = higher privilege tier, horizontal = same tier, different account
- forgery: request/token forged to impersonate legitimate action — see CSRF in Confusables
- directory traversal: manipulating file-path input, e.g.
../../, to access files outside the intended directory
Cryptographic attacks:
- downgrade: forcing a connection to use a weaker, breakable protocol/cipher version
- collision: two different inputs produce the same hash output, undermining integrity guarantees
- birthday: a collision attack that exploits probability — fewer attempts are needed to find any collision than to find a collision with one specific target
Password attacks: spraying (one or a few common passwords tried across many accounts, staying under per-account lockout thresholds), brute force (many/all possible passwords tried against one account or hash — see Confusables).
Indicators (the actual alert signals):
- account lockout
- concurrent session usage: same account active from two places at once
- blocked content: a control silently prevented something — worth investigating why
- impossible travel: logins from geographically incompatible locations in an impossible timeframe — a classic Conditional Access / sign-in log alert
- resource consumption: abnormal CPU/memory/bandwidth use, e.g. cryptomining or DDoS participation
- resource inaccessibility: a service/resource unexpectedly unavailable, possibly indicating attack or failure
- out-of-cycle logging: log activity appearing outside expected/scheduled windows
- published/documented: an organisation's data or credentials found publicly posted, e.g. on a leak site
- missing logs: logs that should exist but don't — often the strongest tampering indicator, since something was deliberately cleared
2.5 Mitigation Techniques
Mitigations map roughly one-to-one against the vectors/vulnerabilities above, and several are literally your day job.
Segmentation — isolating networks/systems to limit lateral movement (VLANs on the network side; Conditional Access location/device-based scoping in your environment). Access control — ACLs (rule-based traffic/resource filtering) and permissions (least-privilege file/system rights).
Application allow list — only explicitly approved software may run, blocking everything else by default (stronger than a blocklist, which only blocks known-bad). Isolation — separating a compromised or high-risk system/segment from the rest of the environment.
Patching — applying vendor updates to close known vulnerabilities (the direct answer to unpatched OS/application vulnerabilities from 2.3). Encryption — protecting data confidentiality at rest/in transit (ties back to Domain 1's cryptographic solutions).
Monitoring — ongoing observation (log review, EDR/XDR alerting) to catch the indicators in 2.4. Least privilege — granting only the minimum access necessary — the direct mitigation for privilege escalation and insider-threat blast radius.
Configuration enforcement — ensuring systems stay compliant with a defined secure baseline (Intune compliance policies are configuration enforcement in production). Decommissioning — properly retiring end-of-life/legacy systems rather than leaving them running unsupported.
Hardening, which itself bundles several sub-techniques:
- encryption
- installation of endpoint protection: Defender for Endpoint itself
- host-based firewall
- HIPS: host intrusion prevention system — blocks detected malicious activity on the host, vs. a host-based IDS which only detects/alerts
- disabling unnecessary ports/protocols
- changing default passwords
- removal of unnecessary software: reduces the attack surface directly
Confusables — Don't Mix These Up
Virus vs. Worm vs. Trojan
| Term | What it is | Key differentiator | Exam tell |
|---|---|---|---|
| Virus | Malicious code attached to a host file | Needs a host file and user action to execute/spread | "Requires the user to open/run a file" |
| Worm | Self-replicating malicious code | Spreads across a network on its own, no user action or host file needed | "Spread automatically across the network without user interaction" |
| Trojan | Malicious code disguised as legitimate software | Relies on deception to get installed; doesn't self-replicate | "Disguised as/masquerading as a legitimate application" |
Phishing vs. Vishing vs. Smishing vs. BEC vs. Pretexting
| Term | What it is | Key differentiator | Exam tell |
|---|---|---|---|
| Phishing | Deceptive email to harvest credentials/deliver malware | Delivery channel is email | "Email with a malicious link/attachment" |
| Vishing | Voice-call phishing | Delivery channel is a phone call | "Caller claiming to be..." |
| Smishing | SMS-based phishing | Delivery channel is text message | "Text message with a link" |
| BEC | Compromised/spoofed business email used for fraud | Targets business processes (wire transfers, payroll), often impersonates an executive | "CEO/CFO email requesting an urgent transfer" |
| Pretexting | A fabricated scenario/identity used to extract info | The technique underlying the deception, channel-agnostic — can ride inside vishing, phishing, or in-person contact | "Inventing a false scenario/identity to justify a request" |
Misinformation vs. Disinformation
| Term | What it is | Key differentiator | Exam tell |
|---|---|---|---|
| Misinformation | False information spread | Spreader believes it or spreads without intent to deceive | "Unintentionally spread false information" |
| Disinformation | Deliberately fabricated false information | Created and spread with intent to deceive/manipulate | "Deliberately fabricated to mislead" |
Brute Force vs. Password Spraying
| Term | What it is | Key differentiator | Exam tell |
|---|---|---|---|
| Brute force | Tries many/all possible passwords | Targets one account (or one hash) exhaustively | "Every possible password against a single account" |
| Password spraying | Tries one/few common passwords | Targets many accounts with the same password(s), staying under lockout thresholds | "Same password tried across many usernames" |
DDoS Amplified vs. Reflected
| Term | What it is | Key differentiator | Exam tell |
|---|---|---|---|
| Amplified | A small request generates a disproportionately large response | The property being exploited is the size increase (e.g. DNS amplification) | "Small query, disproportionately large response" |
| Reflected | Attacker spoofs the victim's source IP so third-party responses are sent to the victim | The property being exploited is misdirection of replies (bounced off an innocent third party) | "Spoofed source IP causes replies to hit the victim" |
XSS vs. SQL Injection vs. Forgery (CSRF-style)
| Term | What it is | Key differentiator | Exam tell |
|---|---|---|---|
| XSS | Malicious script injected into a trusted page, executed in victims' browsers | Targets other users of a site via their browser session | "Script runs in another user's browser when they view the page" |
| SQL injection | Unsanitised input alters a backend database query | Targets the database directly, not other users | "Input manipulates/returns database records" |
| Forgery (CSRF-style) | A forged request is submitted using a victim's already-authenticated session, without their knowledge | Exploits the victim's existing trust/session to perform an unwanted action, rather than injecting code or altering a query | "Victim's browser unknowingly submits a request using their active session" |
Exam Traps
- Virus vs. worm — the exam tests self-propagation as the single deciding factor. If it spreads without any user action, it's a worm, full stop, regardless of what else the malware does.
- Amplified vs. reflected DDoS — these commonly occur together in real attacks, but the exam can ask about either property in isolation; don't assume they're synonyms.
- Brute force vs. spraying — "many passwords, one account" vs. "one password, many accounts." Reversing this is the most common wrong answer.
- Insider threat is not automatically malicious-only — shadow IT and negligent insiders both create risk without hostile intent; don't assume every "internal" stem implies deliberate attack.
- Zero-day vs. unpatched known vulnerability — zero-day means the vendor doesn't know/has no patch yet; an unpatched known CVE with an available patch is a misconfiguration/patch-management failure, not a zero-day.
- Client-based vs. agentless vulnerable software — client-based requires an installed application on the endpoint; agentless is a reachable service/vulnerability with nothing installed locally. Don't default to "client-based" just because a device is involved.
- Pretexting is a technique, not a channel — it can occur over phone, email, or in person; don't confuse it with vishing (which is defined by the channel, not the technique).
- Misinformation vs. disinformation hinges entirely on intent to deceive, not on whether the information is false — both are false; only disinformation is deliberate.
- HIPS vs. host-based IDS — HIPS actively blocks detected malicious activity on the host; an IDS-equivalent only detects and alerts. If the stem says the system "blocked" or "prevented," don't default to "detection" language.
Acronym Table
| Acronym | Expansion | One-line meaning |
|---|---|---|
| BEC | Business Email Compromise | Fraud via a compromised/spoofed business email account |
| DDoS | Distributed Denial of Service | Overwhelming a target using multiple sources |
| DNS | Domain Name System | Resolves hostnames to IP addresses; a common attack target |
| TOCTOU | Time-of-Check to Time-of-Use | Race condition exploiting the gap between checking and using a resource |
| XSS | Cross-Site Scripting | Malicious script injected into a trusted page, run in victims' browsers |
| SQLi | SQL Injection | Malicious input alters a backend database query |
| VM | Virtual Machine | A software-based emulated computer; can be subject to escape attacks |
| RFID | Radio-Frequency Identification | Wireless identification technology used in access badges; can be cloned |
| HIPS | Host Intrusion Prevention System | Endpoint agent that actively blocks detected malicious activity |
| ACL | Access Control List | Rule set controlling allowed/denied traffic or resource access |
| MSP | Managed Service Provider | Third party managing IT/security on an organisation's behalf |
| EOL | End-of-Life | A product no longer sold or supported by its vendor |
Drills: 20 flashcards + 10 exam-realistic questions, at the end of this page.
Interactive drills
Flashcards
Click a card to flip it, then rate how well you knew it — cards you rate lower come back sooner. 20 cards from real study drills, scheduled with spaced repetition.
Due today: 20
Flipped: 0/20
Quiz
10 exam-style questions, easy to hard. Pick an option to see whether you're right, and why.
Score: 0/9
Q1EasyWhich threat actor type is primarily motivated by philosophical or political beliefs, using disruption or defacement to advance a cause rather than for financial gain?
Q2EasyAn employee installs a personal cloud-storage sync client on a work laptop without IT approval to work around slow VPN speeds, unintentionally exposing case files to an unsanctioned service. What best describes this?
Q3EasyWhich malware type is defined by its ability to self-replicate and spread across a network without any user interaction or host file?
Q4MediumA help desk technician receives a call from someone claiming to be a partner law firm's IT administrator, urgently requesting a password reset "before a court filing deadline." Which two concepts combine to describe this attack?
Q5MediumWhich vulnerability describes a flaw where an application checks a resource's state and then acts on it, but the resource changes in the interval between the check and the action?
Q6MediumA DNS resolver forwards a disproportionately large response to a spoofed source address that is actually the intended victim, overwhelming the victim's bandwidth. Which two DDoS properties does this combine?
Q7MediumA Defender for Endpoint review shows the same user account authenticating successfully from Darwin at 08:58 and from a country the user has never visited at 09:03 — a physically impossible transit time. Which indicator category is this?
Q8HardA legacy internal application accepts a "file" URL parameter, and an attacker submits report.php?file=../../../../etc/passwd attempting to read files outside the intended directory. Which attack is being attempted?
../ sequences to escape the intended directory is directory traversal. SQL injection (A) is the closest distractor, but SQLi manipulates a database query, not a filesystem path — no query syntax is present here.Match each indicator (1–4) to the attack/concept (A–D) it most strongly signals.
Indicators:
- An account is locked out after roughly 40 failed logon attempts within 8 seconds from a single source.
- One common password fails against 200 different usernames over an hour, one attempt per account.
- A modified file's computed hash matches the hash of a different, unmodified file.
- Endpoint protection reports no active threats, yet a hidden process keeps re-establishing an outbound connection invisible to the OS's normal process list.
Options: A) Password spraying B) Brute force C) Hash collision D) Rootkit
Answer: 1-B, 2-A, 3-C, 4-D. (1) Many attempts against one account in seconds is brute force. (2) One password across many accounts, staying under lockout thresholds, is spraying. (3) Two different inputs producing the same hash output is a collision.
(4) A process hidden from normal OS visibility while remaining active is the defining behaviour of a rootkit. Reversing 1 and 2 is the most common mistake — the differentiator is always "one account, many passwords" (brute force) vs. "many accounts, one password" (spraying).
Q10Medium, PBQ — log interpretationA SOC analyst reviews an EDR log excerpt:
winword.exe spawning powershell.exe to fetch a payload is the classic malicious-macro delivery chain, followed by mass encryption and a ransom note — ransomware delivered through a weaponised document. Trojan (C) is the closest distractor since both rely on deceptive delivery, but nothing in the log indicates disguise as a software update — the vector here is a document macro, and the payload's behaviour (encrypt + ransom demand) specifically identifies ransomware rather than just "disguised software."