TB.

Security+ SY0-701 · Domain 2

Domain 2: Threats, Vulnerabilities & Mitigations

Why This Domain Matters

Domain 2 is the largest pure-study domain on the exam (22%) and the one a SOC analyst draws on every single shift: it's the taxonomy behind every endpoint alert, every phishing report, and every "why did this account lock out" ticket.

Where Domain 1 gives the vocabulary, Domain 2 gives the actual catalogue of things that go wrong — who does it (2.1), how they get in (2.2), what they exploit (2.3), what it looks like when it happens (2.4), and what to do about it (2.5).

Read it as one continuous story: actor → vector → vulnerability → indicator → mitigation.

Objective-by-Objective Breakdown

2.1 Threat Actors & Motivations

The attack chain — actor, vector, vulnerability, indicator, mitigation, in order

The exam separates who (actor type) from why (motivation) from attributes (how capable/resourced they are) — a stem can test any of the three independently.

Actor types:

  • nation-state: state-sponsored, highest resources/sophistication, often long-dwell espionage
  • unskilled attacker: a.k.a. "script kiddie" — low skill, uses off-the-shelf tools
  • hacktivist: ideologically motivated, disruption/defacement over profit
  • insider threat: current/former employee or contractor abusing legitimate access
  • organized crime: financially motivated, structured, persistent
  • shadow IT: not a malicious actor per se — employees standing up unsanctioned systems/apps, creating risk through negligence rather than intent

Attributes:

  • internal vs. external: is the actor inside or outside the organisation's trust boundary — an insider threat is internal by definition
  • level of resources/funding: nation-states >> organized crime >> hacktivists >> unskilled attackers, as a rough exam ranking
  • level of sophistication/capability: correlates with resources but is tested separately — a well-funded actor can still buy unsophisticated tools

Motivations:

  • data exfiltration
  • espionage: nation-state hallmark
  • service disruption
  • blackmail
  • financial gain: organized crime hallmark
  • philosophical/political beliefs: hacktivist hallmark
  • ethical: e.g. a bug-bounty researcher or "white hat" disclosure motive
  • revenge: common insider-threat driver
  • disruption/chaos
  • war: nation-state, cyberwarfare context

2.2 Threat Vectors & Attack Surfaces

A vector is the specific path an attack travels; the attack surface is the sum of everywhere it could enter. The exam groups vectors into technical categories and a separate human/social-engineering category.

Technical vectors:

  • message-based: email, SMS, instant messaging — still the dominant delivery method
  • image-based: malicious code or payloads embedded in image files
  • file-based: malicious documents/attachments
  • voice call: vishing delivery
  • removable device: USB drops
  • vulnerable software — split into client-based (an installed application with an exploitable flaw, e.g. an outdated PDF reader) vs. agentless (a vulnerable service reachable without any installed client, e.g. an exposed web app)
  • unsupported systems/applications: end-of-support software with no patches
  • unsecure networks: wireless, wired, Bluetooth — each with its own weaknesses
  • open service ports: unnecessarily exposed listening services
  • default credentials: vendor defaults never changed
  • supply chain: risk introduced via MSPs, vendors, and suppliers — this cuts both ways depending on which side of the relationship an organization is on

Human vectors / social engineering — the exam's favourite exploitable "vulnerability" is always the human:

  • Phishing — broad, email-based deception to harvest credentials or deliver malware.
  • Vishing — voice-call phishing.
  • Smishing — SMS-based phishing.
  • Misinformation/disinformation — false information spread (misinformation = spread without intent to deceive; disinformation = deliberately fabricated and spread to deceive — see Confusables).
  • Impersonation — pretending to be a trusted person to manipulate a target.
  • Business email compromise (BEC) — compromising or spoofing a business email account (often executive) to induce fraudulent transfers or data disclosure.
  • Pretexting — inventing a fabricated scenario/identity to extract information (often the mechanism underneath impersonation or vishing).
  • Watering hole — compromising a website the target population is known to visit, waiting for victims to come to the trap rather than pushing the attack out.
  • Brand impersonation — mimicking a trusted brand's look/domain/communications.
  • Typosquatting — registering a misspelled or lookalike domain to catch mistyped URLs.

2.3 Vulnerability Types

Vulnerabilities are grouped by where the weakness lives.

Application:

  • memory injection: malicious code injected into a running process's memory space
  • buffer overflow: input exceeds allocated memory, overwriting adjacent memory — can lead to code execution
  • race conditions — specifically TOCTOU: time-of-check to time-of-use: a resource's state changes between when it's checked and when it's used, exploitable in that window
  • malicious update: a legitimate-seeming update channel used to deliver malicious code — a supply-chain-adjacent risk

OS-based: unpatched or misconfigured operating systems exposing known flaws.

Web-based: SQL injection (unsanitised input alters a backend database query, can read/modify/delete data it shouldn't), cross-site scripting (XSS) (malicious script injected into a trusted web page, executed in the victim's browser context — see Confusables for the CSRF distinction).

Hardware:

  • firmware: low-level device software vulnerabilities, e.g. router/BIOS firmware never updated
  • end-of-life: vendor no longer sells/supports it
  • legacy: outdated but still in use, often because replacement is costly/disruptive

Virtualization: VM escape (code in a guest VM breaks out to affect the host or other VMs — a hypervisor-boundary failure), resource reuse (data remnants from one VM/tenant improperly exposed to the next tenant reusing the same physical resource).

Cloud-specific:

  • vulnerabilities arising from shared-responsibility gaps
  • misconfigured storage/identity
  • multi-tenant exposure unique to cloud platforms

Supply chain: service provider, hardware provider, software provider — risk inherited from any third party in the delivery chain (distinct from 2.2's supply-chain vector: 2.3 is the vulnerability that exists because of that dependency).

Cryptographic: weak algorithms, poor key management, or implementation flaws that undermine confidentiality/integrity guarantees.

Misconfiguration: default settings, excessive permissions, or unhardened services left as-is — the most common and most preventable vulnerability class.

Mobile device: side loading (installing apps from outside the official app store, bypassing vetting), jailbreaking (removing OS-imposed restrictions, eliminating vendor security controls).

Zero-day: a vulnerability unknown to the vendor (no patch exists) — distinct from an unpatched known vulnerability, which just hasn't been remediated yet.

2.4 Indicators of Malicious Activity

This objective is a direct map to what actually populates your Defender for Endpoint alert queue.

Malware attacks:

  • ransomware: encrypts data for extortion
  • trojan: malicious code disguised as legitimate software
  • worm: self-replicates and spreads across a network without user action — the self-propagation is the defining trait
  • spyware: covertly monitors/collects user activity
  • bloatware: unwanted pre-installed software — not necessarily malicious, but expands attack surface
  • virus: malicious code that requires a host file/user action to execute and spread — this is what separates it from a worm
  • keylogger: captures keystrokes
  • logic bomb: dormant code that triggers on a specific condition/date
  • rootkit: embeds at a privileged level to hide its own and other malware's presence

Physical attacks:

  • brute force: repeated physical attempts, e.g. lock picking, or repeated login attempts — context-dependent
  • RFID cloning: duplicating a badge/access card's signal
  • environmental: attacks or failures via HVAC, power, fire suppression manipulation

Network attacks: DDoS — amplified (a small request to a third-party service generates a disproportionately large response directed at the victim, e.g.

DNS amplification) vs. reflected (the attacker spoofs the victim's source IP so replies are reflected onto the victim — amplification and reflection are usually combined, but the exam can test either property alone; see Confusables).

DNS attacks (poisoning, hijacking — corrupting or redirecting the name-to-address lookup so victims are sent to malicious infrastructure while typing the correct address). Wireless attacks (rogue APs, deauthentication).

On-path (attacker positions between two communicating parties to intercept/alter traffic — the modern term for "man-in-the-middle"). Credential replay (captured valid credentials/tokens reused to gain access without cracking them). Malicious code (generic execution of attacker-supplied code across any of the above).

Application attacks:

  • injection: SQLi and similar — untrusted input executed as commands
  • buffer overflow: as in 2.3, but here as an observed attack rather than the underlying flaw
  • replay: a captured legitimate transaction/session resent to repeat its effect
  • privilege escalation: an attacker or process gains rights beyond what was granted — vertical = higher privilege tier, horizontal = same tier, different account
  • forgery: request/token forged to impersonate legitimate action — see CSRF in Confusables
  • directory traversal: manipulating file-path input, e.g. ../../, to access files outside the intended directory

Cryptographic attacks:

  • downgrade: forcing a connection to use a weaker, breakable protocol/cipher version
  • collision: two different inputs produce the same hash output, undermining integrity guarantees
  • birthday: a collision attack that exploits probability — fewer attempts are needed to find any collision than to find a collision with one specific target

Password attacks: spraying (one or a few common passwords tried across many accounts, staying under per-account lockout thresholds), brute force (many/all possible passwords tried against one account or hash — see Confusables).

Indicators (the actual alert signals):

  • account lockout
  • concurrent session usage: same account active from two places at once
  • blocked content: a control silently prevented something — worth investigating why
  • impossible travel: logins from geographically incompatible locations in an impossible timeframe — a classic Conditional Access / sign-in log alert
  • resource consumption: abnormal CPU/memory/bandwidth use, e.g. cryptomining or DDoS participation
  • resource inaccessibility: a service/resource unexpectedly unavailable, possibly indicating attack or failure
  • out-of-cycle logging: log activity appearing outside expected/scheduled windows
  • published/documented: an organisation's data or credentials found publicly posted, e.g. on a leak site
  • missing logs: logs that should exist but don't — often the strongest tampering indicator, since something was deliberately cleared

2.5 Mitigation Techniques

Mitigations map roughly one-to-one against the vectors/vulnerabilities above, and several are literally your day job.

Segmentation — isolating networks/systems to limit lateral movement (VLANs on the network side; Conditional Access location/device-based scoping in your environment). Access control — ACLs (rule-based traffic/resource filtering) and permissions (least-privilege file/system rights).

Application allow list — only explicitly approved software may run, blocking everything else by default (stronger than a blocklist, which only blocks known-bad). Isolation — separating a compromised or high-risk system/segment from the rest of the environment.

Patching — applying vendor updates to close known vulnerabilities (the direct answer to unpatched OS/application vulnerabilities from 2.3). Encryption — protecting data confidentiality at rest/in transit (ties back to Domain 1's cryptographic solutions).

Monitoring — ongoing observation (log review, EDR/XDR alerting) to catch the indicators in 2.4. Least privilege — granting only the minimum access necessary — the direct mitigation for privilege escalation and insider-threat blast radius.

Configuration enforcement — ensuring systems stay compliant with a defined secure baseline (Intune compliance policies are configuration enforcement in production). Decommissioning — properly retiring end-of-life/legacy systems rather than leaving them running unsupported.

Hardening, which itself bundles several sub-techniques:

  • encryption
  • installation of endpoint protection: Defender for Endpoint itself
  • host-based firewall
  • HIPS: host intrusion prevention system — blocks detected malicious activity on the host, vs. a host-based IDS which only detects/alerts
  • disabling unnecessary ports/protocols
  • changing default passwords
  • removal of unnecessary software: reduces the attack surface directly

Confusables — Don't Mix These Up

Virus vs. Worm vs. Trojan

TermWhat it isKey differentiatorExam tell
VirusMalicious code attached to a host fileNeeds a host file and user action to execute/spread"Requires the user to open/run a file"
WormSelf-replicating malicious codeSpreads across a network on its own, no user action or host file needed"Spread automatically across the network without user interaction"
TrojanMalicious code disguised as legitimate softwareRelies on deception to get installed; doesn't self-replicate"Disguised as/masquerading as a legitimate application"

Phishing vs. Vishing vs. Smishing vs. BEC vs. Pretexting

TermWhat it isKey differentiatorExam tell
PhishingDeceptive email to harvest credentials/deliver malwareDelivery channel is email"Email with a malicious link/attachment"
VishingVoice-call phishingDelivery channel is a phone call"Caller claiming to be..."
SmishingSMS-based phishingDelivery channel is text message"Text message with a link"
BECCompromised/spoofed business email used for fraudTargets business processes (wire transfers, payroll), often impersonates an executive"CEO/CFO email requesting an urgent transfer"
PretextingA fabricated scenario/identity used to extract infoThe technique underlying the deception, channel-agnostic — can ride inside vishing, phishing, or in-person contact"Inventing a false scenario/identity to justify a request"

Misinformation vs. Disinformation

TermWhat it isKey differentiatorExam tell
MisinformationFalse information spreadSpreader believes it or spreads without intent to deceive"Unintentionally spread false information"
DisinformationDeliberately fabricated false informationCreated and spread with intent to deceive/manipulate"Deliberately fabricated to mislead"

Brute Force vs. Password Spraying

TermWhat it isKey differentiatorExam tell
Brute forceTries many/all possible passwordsTargets one account (or one hash) exhaustively"Every possible password against a single account"
Password sprayingTries one/few common passwordsTargets many accounts with the same password(s), staying under lockout thresholds"Same password tried across many usernames"

DDoS Amplified vs. Reflected

TermWhat it isKey differentiatorExam tell
AmplifiedA small request generates a disproportionately large responseThe property being exploited is the size increase (e.g. DNS amplification)"Small query, disproportionately large response"
ReflectedAttacker spoofs the victim's source IP so third-party responses are sent to the victimThe property being exploited is misdirection of replies (bounced off an innocent third party)"Spoofed source IP causes replies to hit the victim"

XSS vs. SQL Injection vs. Forgery (CSRF-style)

TermWhat it isKey differentiatorExam tell
XSSMalicious script injected into a trusted page, executed in victims' browsersTargets other users of a site via their browser session"Script runs in another user's browser when they view the page"
SQL injectionUnsanitised input alters a backend database queryTargets the database directly, not other users"Input manipulates/returns database records"
Forgery (CSRF-style)A forged request is submitted using a victim's already-authenticated session, without their knowledgeExploits the victim's existing trust/session to perform an unwanted action, rather than injecting code or altering a query"Victim's browser unknowingly submits a request using their active session"

Exam Traps

  • Virus vs. worm — the exam tests self-propagation as the single deciding factor. If it spreads without any user action, it's a worm, full stop, regardless of what else the malware does.
  • Amplified vs. reflected DDoS — these commonly occur together in real attacks, but the exam can ask about either property in isolation; don't assume they're synonyms.
  • Brute force vs. spraying — "many passwords, one account" vs. "one password, many accounts." Reversing this is the most common wrong answer.
  • Insider threat is not automatically malicious-only — shadow IT and negligent insiders both create risk without hostile intent; don't assume every "internal" stem implies deliberate attack.
  • Zero-day vs. unpatched known vulnerability — zero-day means the vendor doesn't know/has no patch yet; an unpatched known CVE with an available patch is a misconfiguration/patch-management failure, not a zero-day.
  • Client-based vs. agentless vulnerable software — client-based requires an installed application on the endpoint; agentless is a reachable service/vulnerability with nothing installed locally. Don't default to "client-based" just because a device is involved.
  • Pretexting is a technique, not a channel — it can occur over phone, email, or in person; don't confuse it with vishing (which is defined by the channel, not the technique).
  • Misinformation vs. disinformation hinges entirely on intent to deceive, not on whether the information is false — both are false; only disinformation is deliberate.
  • HIPS vs. host-based IDS — HIPS actively blocks detected malicious activity on the host; an IDS-equivalent only detects and alerts. If the stem says the system "blocked" or "prevented," don't default to "detection" language.

Acronym Table

AcronymExpansionOne-line meaning
BECBusiness Email CompromiseFraud via a compromised/spoofed business email account
DDoSDistributed Denial of ServiceOverwhelming a target using multiple sources
DNSDomain Name SystemResolves hostnames to IP addresses; a common attack target
TOCTOUTime-of-Check to Time-of-UseRace condition exploiting the gap between checking and using a resource
XSSCross-Site ScriptingMalicious script injected into a trusted page, run in victims' browsers
SQLiSQL InjectionMalicious input alters a backend database query
VMVirtual MachineA software-based emulated computer; can be subject to escape attacks
RFIDRadio-Frequency IdentificationWireless identification technology used in access badges; can be cloned
HIPSHost Intrusion Prevention SystemEndpoint agent that actively blocks detected malicious activity
ACLAccess Control ListRule set controlling allowed/denied traffic or resource access
MSPManaged Service ProviderThird party managing IT/security on an organisation's behalf
EOLEnd-of-LifeA product no longer sold or supported by its vendor

Drills: 20 flashcards + 10 exam-realistic questions, at the end of this page.

Interactive drills

Flashcards

Click a card to flip it, then rate how well you knew it — cards you rate lower come back sooner. 20 cards from real study drills, scheduled with spaced repetition.

Due today: 20

Flipped: 0/20

Quiz

10 exam-style questions, easy to hard. Pick an option to see whether you're right, and why.

Score: 0/9

Q1EasyWhich threat actor type is primarily motivated by philosophical or political beliefs, using disruption or defacement to advance a cause rather than for financial gain?

Q2EasyAn employee installs a personal cloud-storage sync client on a work laptop without IT approval to work around slow VPN speeds, unintentionally exposing case files to an unsanctioned service. What best describes this?

Q3EasyWhich malware type is defined by its ability to self-replicate and spread across a network without any user interaction or host file?

Q4MediumA help desk technician receives a call from someone claiming to be a partner law firm's IT administrator, urgently requesting a password reset "before a court filing deadline." Which two concepts combine to describe this attack?

Q5MediumWhich vulnerability describes a flaw where an application checks a resource's state and then acts on it, but the resource changes in the interval between the check and the action?

Q6MediumA DNS resolver forwards a disproportionately large response to a spoofed source address that is actually the intended victim, overwhelming the victim's bandwidth. Which two DDoS properties does this combine?

Q7MediumA Defender for Endpoint review shows the same user account authenticating successfully from Darwin at 08:58 and from a country the user has never visited at 09:03 — a physically impossible transit time. Which indicator category is this?

Q8HardA legacy internal application accepts a "file" URL parameter, and an attacker submits report.php?file=../../../../etc/passwd attempting to read files outside the intended directory. Which attack is being attempted?

Q9Hard, PBQ — matching

Match each indicator (1–4) to the attack/concept (A–D) it most strongly signals.

Indicators:

  1. An account is locked out after roughly 40 failed logon attempts within 8 seconds from a single source.
  2. One common password fails against 200 different usernames over an hour, one attempt per account.
  3. A modified file's computed hash matches the hash of a different, unmodified file.
  4. Endpoint protection reports no active threats, yet a hidden process keeps re-establishing an outbound connection invisible to the OS's normal process list.

Options: A) Password spraying B) Brute force C) Hash collision D) Rootkit

Q10Medium, PBQ — log interpretationA SOC analyst reviews an EDR log excerpt: