Part 3 of 6 | Domain 2.0 | 24% of the Examination
Introduction
Cybersecurity threats can originate from organized criminal groups, foreign governments, employees, compromised suppliers, malicious software, and simple human mistakes.
Security professionals need to understand who poses a threat, how attacks occur, which weaknesses make systems vulnerable, and what evidence may indicate that an attack has taken place.
This lesson covers the six objectives in Domain 2.0 of the CompTIA Security+ SY0-801 examination:
- 2.1: Explain characteristics of threats and vulnerabilities.
- 2.2: Describe common threat actors and motivations.
- 2.3: Describe threat vectors and sources.
- 2.4: Explain types of vulnerabilities and attack surfaces.
- 2.5: Given a scenario, analyze indicators of malicious activity.
- 2.6: Summarize threats and vulnerabilities associated with artificial intelligence (AI) usage.
The goal is to understand each concept and recognize it in the scenario-based questions commonly associated with security certification examinations.
2.1 — Explain Characteristics of Threats and Vulnerabilities
Understanding Threats, Vulnerabilities, and Risk
A threat is something capable of causing harm to an organization, system, individual, or information asset.
A vulnerability is a weakness that could be exploited by a threat.
Risk represents the potential for an adverse event, considering factors such as likelihood and impact.
For example, a company operates an internet-facing application that contains a known security vulnerability.
The vulnerability is the weakness in the application. A criminal group seeking to exploit it represents a threat. The possibility that exploitation will cause unauthorized access, data theft, or service disruption represents risk.
A vulnerability does not necessarily mean an attack has occurred. An attack is an attempt to exploit or otherwise compromise a target.
Threat Feeds
Threat feeds provide information about potential or known security threats.
They may include malicious IP addresses, suspicious domains, malware hashes, known vulnerabilities, indicators of compromise, and observed attacker behavior.
A security information and event management (SIEM) platform can use this information to enrich security events and support investigations.
Threat feeds vary in accuracy, relevance, freshness, and reliability. A domain appearing in a threat feed is not necessarily sufficient evidence to conclude that every interaction with it is malicious.
Threat Intelligence Sources
Threat intelligence can originate from several sources.
| Source | Description |
|---|---|
| Open-source intelligence (OSINT) | Publicly accessible information, including security reports and research |
| Commercial intelligence | Information supplied by commercial threat intelligence providers |
| Government advisories | Alerts and security guidance from national cybersecurity organizations |
| Information-sharing communities | Threat intelligence exchanged between trusted organizations |
| Internal intelligence | Information derived from the organization's own logs, alerts, investigations, and incidents |
| Industry groups | Threat information shared within a particular sector |
Threat intelligence differs from raw threat data because intelligence includes analysis and context that helps decision-makers understand relevance and possible action.
Likelihood
Likelihood describes the probability or estimated chance that a particular threat event will occur.
Factors influencing likelihood include attacker interest, vulnerability exploitability, system exposure, existing safeguards, and evidence of active exploitation.
An internet-facing application with a widely exploited vulnerability may have greater likelihood of compromise than an isolated system with a difficult-to-exploit weakness.
Impact
Impact describes the consequences if a threat event occurs.
Potential consequences include financial loss, operational downtime, compromised information, regulatory penalties, reputational damage, and physical harm.
Risk assessment considers both likelihood and consequences rather than relying on technical severity alone.
Exam distinction: Likelihood concerns the chance of an event; impact concerns its consequences.
Threat Intelligence Life Cycle
Threat intelligence is developed through a recurring process.
| Stage | Purpose |
|---|---|
| Direction | Establish intelligence requirements and priorities |
| Collection | Gather relevant data from selected sources |
| Processing | Normalize, organize, and prepare collected information |
| Analysis | Determine meaning, relevance, credibility, and implications |
| Dissemination | Deliver useful intelligence to the intended audience |
| Feedback | Evaluate usefulness and refine future requirements |
The cycle improves the quality and relevance of intelligence over time.
Understanding Vulnerabilities
Vulnerabilities may exist in software, hardware, applications, network configurations, identity systems, business processes, or human activities.
Examples include unsupported operating systems, missing security updates, insecure permissions, exposed credentials, and defective application logic.
Vulnerability Scoring: CVSS
The Common Vulnerability Scoring System (CVSS) provides a standardized framework for describing and scoring the severity of software vulnerabilities.
CVSS base scores commonly range from 0.0 to 10.0.
| Score | Severity |
|---|---|
| 0.0 | None |
| 0.1–3.9 | Low |
| 4.0–6.9 | Medium |
| 7.0–8.9 | High |
| 9.0–10.0 | Critical |
CVSS considers characteristics such as exploit conditions and potential security impact. The precise metrics depend on the CVSS version.
A CVSS score indicates severity under the scoring model. It does not, by itself, determine the real-world risk to every organization.
Common Vulnerabilities and Exposures (CVE)
CVE is a standardized identification system for publicly disclosed cybersecurity vulnerabilities.
A CVE identifier has a format such as CVE-2026-12345, used here as an illustrative identifier rather than a claim about a real vulnerability.
CVE identifiers help different vendors, vulnerability scanners, advisories, and security teams refer to the same issue.
CVE versus CVSS:
- CVE identifies a vulnerability.
- CVSS describes its severity.
The National Vulnerability Database (NVD) is a separate resource that enriches published vulnerability information with additional analysis and metadata; it is not itself the CVE identifier system.
Vulnerability Prioritization
A security team may discover hundreds of vulnerabilities but cannot necessarily address all of them simultaneously.
Prioritization considers CVSS severity together with factors such as:
- Whether attackers are actively exploiting the issue.
- Whether the vulnerable system is exposed to the internet.
- The business importance of the affected asset.
- Potential impact on confidentiality, integrity, or availability.
- Whether exploitation requires authentication or other special conditions.
- Existing mitigating controls.
- Availability and operational risk of remediation.
Exam scenario: Two vulnerabilities affect an organization. One has a higher CVSS score on an isolated test system. The other has a slightly lower score but is actively exploited on an internet-facing production server.
The second vulnerability may deserve higher operational priority because organizational exposure and exploitation evidence affect risk.
Objective 2.1 Review
Candidates should be able to distinguish threats, vulnerabilities, and risk; interpret CVSS and CVE references; understand threat intelligence sources and life cycles; and determine why contextual prioritization matters.
2.2 — Describe Common Threat Actors and Motivations
A threat actor is an individual, group, or organization capable of causing a cybersecurity incident.
Threat actors differ in their objectives, sophistication, funding, resources, and access to target systems.
Common Threat Actors
Crime Syndicates and Organized Crime
Organized cybercriminal groups conduct coordinated activities for financial benefit.
Their operations may include ransomware, data theft, payment fraud, extortion, and trafficking in stolen credentials.
Organized groups can be highly specialized, with different individuals or affiliates responsible for gaining access, developing malicious tools, negotiating payments, or laundering proceeds.
Terrorists
Terrorist organizations may use cyberattacks to spread fear, disrupt essential services, promote ideological objectives, or support broader campaigns.
Targets may include government systems, transportation, communications, or public infrastructure.
The defining factor is the actor's purpose, not a specific attack technique.
Unskilled Attackers
Unskilled attackers have limited technical ability and may depend on publicly available tools, prewritten scripts, or instructions created by others.
They may seek entertainment, recognition, experimentation, or opportunistic financial gain.
Limited sophistication does not mean they cannot cause substantial damage.
Hacktivists
Hacktivists use cyber activity to advance a political, social, or ideological cause.
Typical activities may include website defacement, information leaks, or disruptive denial-of-service attacks.
The primary distinguishing characteristic is the activist motivation rather than financial profit.
Insiders
Insiders are people with legitimate access to an organization's systems or information.
Examples include employees, administrators, contractors, and trusted business partners.
A malicious insider may misuse authorized access to steal information or sabotage systems.
An insider is not necessarily malicious, however. Accidental activity is a separate threat category.
Accidental or Unintentional Actors
Unintentional threat actors cause security incidents through mistakes, carelessness, or misunderstanding.
Examples include sending sensitive information to the wrong recipient, incorrectly configuring cloud permissions, or unintentionally disclosing protected material.
The security consequences can resemble those of intentional attacks, even though the motivation differs.
Competitors
Competitors may seek unauthorized access to trade secrets, product plans, financial data, customer lists, or other strategically valuable information.
The objective may be to gain a business advantage.
Ordinary lawful competitive research is not inherently a cybersecurity attack.
State-Sponsored Actors
State-sponsored actors receive support, direction, or resources from a government.
Their activities may involve espionage, strategic disruption, theft of intellectual property, influence operations, or preparation for conflict.
They may have significant resources, specialized capabilities, and long-term operational objectives.
Threat Actor Motivations
| Motivation | Meaning | Illustrative scenario |
|---|---|---|
| Financial | Obtaining money or monetary benefit | Criminals steal payment information |
| Influence | Shaping decisions or perceptions | A campaign attempts to manipulate public opinion |
| Intellectual property | Obtaining proprietary knowledge | Theft of confidential product designs |
| Notoriety | Seeking attention or recognition | An attacker publicizes a website compromise |
| Espionage | Secretly obtaining sensitive intelligence | Theft of classified or strategic information |
| Fear or chaos | Creating disruption or panic | Coordinated attacks disrupt public services |
| Extortion | Coercing a victim for payment or concessions | Threatening to publish stolen records |
| General curiosity | Exploring systems without a defined harmful goal | Unauthorized experimentation |
| Revenge | Retaliating for a perceived grievance | A former employee damages company records |
| Ideological | Advancing a belief or cause | Attack motivated by a social movement |
| Political | Influencing political outcomes | Targeting an election-related service |
| Ethical | Pursuing a perceived security or moral objective | Research intended to expose a weakness, potentially without authorization |
Motivations can overlap. A criminal group might seek money through extortion, while a state-sponsored group might conduct espionage to acquire intellectual property.
An ethical intention does not automatically make unauthorized access lawful or acceptable.
Threat Actor Attributes
Internal Versus External
Internal actors possess legitimate organizational access or a trusted relationship with the organization.
External actors operate without that legitimate internal position.
An internal actor may already have knowledge of systems and business processes, while an external actor may first need to establish access.
Resources and Funding
Resources include money, equipment, personnel, infrastructure, specialist knowledge, and time.
An actor with significant funding may sustain long-term operations and develop specialized capabilities.
Sophistication and Capability
Sophistication concerns technical expertise, planning, and operational methods.
Capabilities concern what the actor can actually accomplish with available knowledge, tools, and access.
A highly sophisticated attacker may develop customized exploits, while a less sophisticated attacker may rely on commodity malware.
Exam scenario: A government-supported group spends several months attempting to collect sensitive aerospace research.
The most likely actor is state-sponsored, and the likely motivation is espionage or intellectual property acquisition.
2.3 — Describe Threat Vectors and Sources
A threat vector is the route or method through which a threat may reach a target.
A threat source is the person, system, organization, or condition from which a threat originates.
Threat vectors extend beyond email and malicious websites. They include devices, suppliers, physical access, wireless signals, identity systems, and trusted administrative tools.
Advanced Persistent Threat (APT)
An advanced persistent threat refers to a capable adversary or sustained intrusion campaign characterized by significant resources, planning, and long-term objectives.
An APT may seek continued access to sensitive systems, intelligence gathering, or strategic advantage.
An APT is not necessarily a single malware family. It describes a threat actor or sustained threat activity.
Message-Based Threat Vectors
Email can deliver fraudulent messages, malicious links, attachments, and impersonation attempts.
A message appearing to originate from a trusted executive may attempt to induce a financial transfer or disclose credentials.
Short Message Service (SMS)
SMS provides a mobile messaging channel that attackers may misuse for fraudulent notices and malicious links.
SMS-based phishing is called smishing.
Rich Communication Services (RCS)
RCS is a modern messaging standard supporting richer communication features than traditional SMS.
As with other messaging systems, attackers may misuse it for impersonation, fraudulent links, or social engineering.
Instant Messaging
Instant messaging platforms may be exploited through compromised contacts, deceptive messages, malicious links, or unauthorized file sharing.
Collaboration Tools
Workplace collaboration services can be abused through fraudulent invitations, compromised accounts, malicious shared files, or deceptive conversations.
The appearance of an internal business communication may increase the credibility of a malicious message.
Image-Based Threat Vectors
Quick Response (QR) Codes
QR codes store machine-readable information, commonly including website addresses.
A malicious QR code may direct a person to a phishing website or other unsafe destination.
The term quishing describes phishing conducted through QR codes.
Embedded Content
Images or media content may contain links, embedded objects, or specially crafted data intended to exploit vulnerable software.
The risk depends on how the receiving application processes the content.
CAPTCHA
CAPTCHA technology attempts to distinguish human interaction from automated activity.
Attackers may imitate CAPTCHA interfaces to make malicious instructions or fraudulent websites appear legitimate.
CAPTCHA systems are not inherently malicious; the threat arises from deceptive use or exploitation.
Attachment-Based Threat Vectors
Embedded Macros
Macros automate functions within supported documents.
Malicious macros may be used to trigger unauthorized behavior when permitted by the document application and its security configuration.
Rich Text Format (RTF) Documents
RTF files support formatted text and can expose weaknesses in applications that process them.
A crafted document may exploit a vulnerable parser or related component.
Portable Document Format (PDF)
PDF files can contain complex document structures, links, forms, and other supported content.
Malicious PDFs may exploit software vulnerabilities or direct readers to fraudulent destinations.
A file extension alone does not establish whether an attachment is safe.
Browser-Based Threat Vectors
Browser Extensions
Extensions may receive permissions to interact with websites, browser content, or user information.
A malicious or compromised extension could misuse those permissions.
JavaScript
JavaScript is widely used for legitimate website functionality.
Attackers may exploit application weaknesses involving JavaScript, including cross-site scripting and other browser-based attacks.
Password Managers
Password managers protect and organize credentials but may become security targets.
Compromise of a manager, its account, endpoint, or browser integration can create significant exposure.
Cookies
Cookies store data associated with website interactions and sessions.
Some cookies contain session identifiers or other sensitive state.
Stolen session cookies may allow unauthorized access when a service accepts them as proof of an authenticated session.
Session Tokens
Session tokens represent an authenticated session or authorized interaction.
If a valid token is stolen and successfully reused, an attacker may gain access without knowing the user's password.
Network-Based Threat Vectors
Infrastructure Devices
Routers, switches, firewalls, and network appliances may be targeted through exposed management interfaces, vulnerable firmware, or compromised credentials.
Compromise can affect network traffic and access across multiple systems.
Virtualized Devices
Virtual machines, virtual appliances, virtual switches, and other virtual infrastructure components may contain security weaknesses.
Misconfigured virtual networking or compromised management systems can expose several workloads.
Session Keys
Session keys protect communications during an established session.
If an attacker obtains usable session-key material, the confidentiality or integrity of protected communications may be compromised, depending on the protocol and circumstances.
Remote Access Threat Vectors
Remote Desktop
Remote desktop technology permits interactive access to another computer.
Weak authentication, exposed services, or compromised accounts can turn remote access into an intrusion path.
Virtual Network Computing (VNC)
VNC provides remote graphical access.
Security depends on authentication, encryption, service configuration, and network exposure.
Virtual Private Network (VPN)
VPNs create protected network connections.
Compromised VPN credentials, vulnerabilities, or unsafe configurations may provide attackers with access to internal systems.
A VPN connection does not automatically make the connected identity trustworthy.
Endpoint-Based Threat Vectors
Mobile Devices
Smartphones can expose organizational data through malicious applications, phishing, operating system vulnerabilities, or device compromise.
Workstations
Workstations are common targets because they handle user activity, documents, browsers, and organizational credentials.
Servers
Servers may expose valuable data or business services. Vulnerabilities and compromised service accounts can have substantial consequences.
Tablets
Tablets share many mobile-device risks, including application permissions, operating system vulnerabilities, and unauthorized data access.
Trusted Devices
A previously trusted device may become compromised while retaining network access or organizational privileges.
Trust based only on prior approval can create security exposure.
Built-In Tools
Operating systems contain legitimate administrative and diagnostic utilities.
Attackers may abuse these built-in capabilities for unauthorized activities.
Living-off-the-Land Tools
Living-off-the-land attacks misuse existing legitimate utilities, services, and system capabilities rather than depending entirely on newly installed malicious software.
This can make malicious activity harder to distinguish from authorized administration.
Exam distinction: A legitimate utility is not inherently malicious. The context, intent, authorization, and observed behavior determine whether its use is suspicious.
Supply Chain-Based Threat Vectors
Third-Party Providers
Vendors may have access to organizational systems, information, or software development processes.
A provider compromise can introduce risk to the organizations that depend on it.
Managed Service Providers (MSPs)
MSPs frequently administer systems for several customers.
Compromise of a privileged MSP account or management platform can affect multiple client environments.
Logistics Providers
Logistics providers may handle equipment, deliveries, replacement parts, or sensitive business information.
Risks include device tampering, shipment diversion, and compromise during transport.
Software as a Service (SaaS) Providers
SaaS providers host applications and data on behalf of customers.
Provider compromise, insecure integrations, excessive permissions, or misconfigurations may affect customer information.
External Media-Based Threat Vectors
Malicious USB Devices
USB devices may carry malicious files, exploit device-handling weaknesses, or imitate other kinds of USB hardware.
The presence of a physical connector does not establish a device's identity or trustworthiness.
Human-Based Threat Vectors
Impersonation
An attacker pretends to be an authorized person, such as an executive, administrator, vendor, or support representative.
Contractors
Contractors may possess legitimate access but may work under different employment, management, or technical arrangements.
Their access can become a threat vector if compromised or improperly managed.
Visitors
Visitors may gain physical proximity to sensitive equipment, documents, or controlled locations.
Biometrics
Biometric systems use characteristics such as fingerprints or facial features.
Threats include presentation attacks, compromised biometric templates, and weaknesses in verification systems.
Watering Hole
A watering-hole attack compromises or imitates a website frequently visited by a particular group of potential victims.
Rather than contacting each target individually, the attacker positions the malicious content where intended victims are likely to encounter it.
Internet of Things (IoT)-Based Threat Vectors
IoT equipment includes network-connected devices that perform specialized functions.
Cameras
Compromised cameras can expose video, credentials, network access, or embedded computing capabilities.
Sensors
Sensors may collect measurements or control-related information.
Compromised sensors may provide misleading readings or become entry points into connected systems.
Printers
Network-connected printers may store documents, credentials, logs, or configuration information.
Weaknesses in their firmware or administration can expose sensitive resources.
Operational Technology (OT)-Based Threat Vectors
Operational technology monitors or controls physical and industrial processes.
Examples include industrial control systems, programmable logic controllers, and equipment used in manufacturing or utilities.
An OT compromise may affect physical safety, production reliability, or essential services.
Physical-Based Threat Vectors
Locks and Keys
Lost, stolen, duplicated, or improperly managed keys may allow unauthorized entry.
Access Vestibules
Access vestibules, sometimes called mantraps, regulate movement between controlled areas.
Failures in their physical or procedural controls may permit unauthorized access.
Access Passes
Access badges and passes identify individuals permitted to enter certain facilities.
Stolen, cloned, shared, or improperly deactivated passes may undermine access restrictions.
Signal-Based Threat Vectors
Bluetooth
Bluetooth supports short-range wireless communications.
Weak pairing, vulnerable implementations, or unauthorized connections can introduce security risks.
Radio Frequency (RF)
RF signals support many wireless technologies.
Threats may include interception, interference, spoofing, or unauthorized transmissions.
Near-Field Communications (NFC)
NFC supports very short-range communications, commonly for payment, access, and device interactions.
Security concerns may include unauthorized reading, relay attacks, or impersonation under applicable conditions.
Objective 2.3 Review
Candidates must recognize how threats can enter an environment through communication channels, endpoints, infrastructure, suppliers, human interactions, physical access, and wireless technologies.
A single incident may involve several vectors.
For example, a compromised supplier account might distribute a malicious attachment through a collaboration platform, combining supply chain, identity, messaging, and attachment-based exposure.
2.4 — Explain Types of Vulnerabilities and Attack Surfaces
An attack surface is the collection of interfaces, systems, identities, data, and access paths through which an attacker may attempt to interact with or compromise a target.
Reducing unnecessary exposure helps limit attack opportunities.
Unsupported Products
Unsupported products no longer receive the support or security maintenance required by their users.
A newly discovered vulnerability may remain unpatched if the vendor no longer provides updates.
Unsupported does not automatically mean compromised, but it increases management difficulty and long-term exposure.
Unpatched Systems
An unpatched system lacks one or more applicable updates.
Missing security patches can leave known vulnerabilities exploitable.
The significance depends on the vulnerability, system exposure, compensating controls, and availability of exploitation methods.
Obsolete Systems
Obsolete systems rely on outdated technology that may no longer meet operational or security requirements.
Obsolete and unsupported are related but distinct: technology may be old while still receiving support, or become unsupported even though it remains operationally necessary.
Unmanaged Systems
Unmanaged systems operate without adequate organizational visibility or security administration.
They may lack inventory records, approved configurations, security monitoring, or routine maintenance.
Unknown assets complicate vulnerability assessment and incident response.
Ports and Services
Network ports identify communication endpoints used by network services.
Unnecessary exposed services expand the potential attack surface.
A legitimately required open port is not automatically a vulnerability. Risk depends on the service, its configuration, access restrictions, and security posture.
Application Vulnerabilities
Applications may contain defects in business logic, data validation, authentication, memory handling, or dependencies.
Race Conditions
A race condition occurs when the outcome of an operation depends on the timing or ordering of concurrent actions.
An exploitable race condition may allow behavior that should not be permitted.
Time-of-Check and Time-of-Use (TOC/TOU)
A time-of-check/time-of-use vulnerability occurs when a condition is checked, but the relevant state changes before the associated action is completed.
For example, an application verifies that a resource is safe and later uses it without ensuring the original condition still holds.
An attacker may exploit the interval between verification and use.
Malicious Updates
An update package may be compromised or deliberately altered to include harmful functionality.
Because update mechanisms often have elevated trust, malicious updates can affect many systems.
Code Vulnerabilities
Hardcoded Secrets
Hardcoded secrets are credentials, passwords, API keys, or other sensitive values embedded directly in source code or application components.
If exposed through repositories, binaries, logs, or application distribution, they may provide unauthorized access.
Unsafe Exception Handling
Exception handling controls application behavior when errors occur.
Poor exception handling may expose stack traces, sensitive configuration values, internal paths, or other information useful to attackers.
It may also cause an application to fail insecurely.
Operating System-Based Vulnerabilities
Operating systems may contain vulnerabilities affecting memory handling, permissions, services, authentication, or kernel functionality.
A successful exploit could lead to unauthorized access, privilege escalation, or system compromise.
Virtualization Vulnerabilities
Virtualization introduces components such as hypervisors, virtual machines, virtual networking, and management interfaces.
Weak isolation, vulnerable hypervisors, or compromised management systems can threaten multiple hosted workloads.
Zero-Day Vulnerabilities
A zero-day vulnerability is a vulnerability for which defenders or the affected vendor have had no meaningful advance opportunity to develop and deploy a fix before exploitation or disclosure, depending on usage.
A zero-day exploit targets such a vulnerability.
The term does not mean the vulnerability has a CVSS score of zero.
Cryptographic Vulnerabilities
Cryptographic weaknesses can result from obsolete algorithms, poor key management, incorrect implementation, unsafe protocol configuration, or inadequate randomness.
Strong encryption algorithms do not compensate for exposed encryption keys.
Unmanaged or Stale Credentials
Stale credentials include accounts, passwords, tokens, or keys that remain usable after their original business purpose has ended.
Examples include accounts belonging to departed employees and forgotten service credentials.
They may provide attackers with access that is unlikely to attract immediate attention.
Rogue Devices
A rogue device is an unauthorized or malicious device connected to an environment.
Examples include an unauthorized wireless access point or an unfamiliar computer connected to a protected network.
Shadow IT
Shadow IT refers to technology adopted or operated outside approved organizational oversight.
Employees might store business files in an unapproved cloud application or use an unsanctioned service to process sensitive information.
The primary problem is lack of visibility, governance, and consistent protection.
Wireless and Low-Powered Communications
Wireless technologies may suffer from weak authentication, insufficient encryption, vulnerable implementations, or signal-based attacks.
Low-powered devices can also have limited processing resources and security-maintenance capabilities.
Large Language Models (LLMs)
LLMs introduce new attack surfaces involving prompts, training or retrieval data, external tools, model outputs, and sensitive information.
Examples include prompt injection, disclosure of private information, and excessive authority granted to AI-connected tools.
Objective 2.6 explores AI-related risks in more detail.
Identity Providers
Identity providers manage authentication and related identity services.
Compromise or misconfiguration may affect numerous connected applications through federation, single sign-on, or identity synchronization.
Mobile Devices
Mobile devices introduce risks involving insecure applications, lost devices, compromised credentials, outdated software, and sensitive data stored locally or accessed remotely.
Misconfiguration
A misconfiguration occurs when a system is set up in an insecure or unintended way.
Examples include excessive permissions, default credentials, exposed administrative interfaces, and incorrectly configured access controls.
A system can be fully patched and still be insecure because of its configuration.
Public Repositories
Public code repositories may expose sensitive data when developers accidentally commit secrets, private configuration files, internal documentation, or confidential source code.
Public accessibility is not inherently a vulnerability. The risk depends on the information exposed.
Public Object Storage
Cloud object storage may unintentionally expose data through overly permissive access policies or publicly accessible objects.
An organization may experience a data disclosure without a software exploit if stored information is configured for unintended public access.
Objective 2.4 Review
The examination may describe a system weakness and ask candidates to identify its category.
A forgotten employee account suggests stale credentials. An unapproved cloud service suggests shadow IT. An exposed storage bucket suggests misconfiguration or public object storage. An application whose authorization state changes between validation and execution suggests a TOC/TOU race condition.
2.5 — Given a Scenario, Analyze Indicators of Malicious Activity
Malicious activity can produce evidence in system logs, network traffic, files, processes, authentication records, and user reports.
An indicator of compromise (IOC) is observable information that may suggest unauthorized or malicious activity.
Not every indicator proves a compromise. Evidence must be interpreted in context.
Malware Attacks
Malware is software or code designed to perform unauthorized, harmful, deceptive, or otherwise malicious actions.
Ransomware
Ransomware attempts to deny access to information or systems, commonly through encryption, and demands payment or another concession.
Modern ransomware attacks may also involve theft of information and threats to publish it.
Typical indicators: Unexpected mass file encryption, ransom notes, inaccessible files, and unusual file modifications.
Trojan
A Trojan is malicious software that disguises itself as legitimate or desirable software.
A Trojan depends on deceptive presentation or delivery; it does not inherently self-replicate.
Worm
A worm is malware capable of spreading between systems, often through network-accessible vulnerabilities or other propagation mechanisms.
Worm activity may cause rapid infection and substantial network traffic.
Spyware
Spyware secretly gathers information about users, devices, or activity.
It may collect browsing information, credentials, or other sensitive data.
Adware
Adware displays advertisements, sometimes in intrusive or deceptive ways.
Not all advertising-supported software is malware. Adware becomes a security concern when it engages in unwanted, deceptive, or harmful behavior.
Virus
A computer virus attaches to or infects another file, program, or component and replicates when the infected host is activated.
Virus versus worm: A virus normally requires a host component and execution conditions; a worm is designed for independent propagation.
Rootkit
A rootkit hides malicious activity or provides concealed privileged access.
It may manipulate operating system behavior to make files, processes, or other evidence difficult to detect.
Keylogger
A keylogger records keyboard input.
Malicious keyloggers may capture credentials, messages, and confidential information.
Logic Bomb
A logic bomb is malicious functionality designed to activate when a predefined condition occurs.
For example, harmful code might be triggered by a particular date or system event.
Fileless Malware
Fileless malware relies heavily on memory, legitimate system processes, or built-in capabilities rather than conventional malicious executable files stored on disk.
It may leave fewer traditional file artifacts, but it can still generate process, memory, network, or log evidence.
Physical Attacks
| Attack | Description |
|---|---|
| Tailgating | An unauthorized person follows an authorized person into a restricted area |
| Shoulder surfing | Observing sensitive information over someone's shoulder or from nearby |
| Skimming | Illegitimately collecting payment-card or similar data using a compromised reader |
| Forced entry | Gaining access by physically defeating barriers or access restrictions |
These attacks exploit physical access and human behavior rather than necessarily requiring software vulnerabilities.
Network Attacks
Distributed Denial of Service (DDoS)
A DDoS attack uses multiple sources to overwhelm a target's network, systems, or application resources.
The primary objective is often to disrupt availability.
Protocol Downgrade
A protocol downgrade attack attempts to force communicating parties to use an older or weaker security protocol or mode.
The resulting connection may provide weaker confidentiality or integrity protections.
Rogue Network Components
A rogue network device is an unauthorized component, such as an access point, that may intercept communications or provide an unintended connection path.
Sniffing
Sniffing involves capturing or observing network traffic.
Traffic analysis may be legitimate during authorized troubleshooting. Malicious sniffing seeks unauthorized information.
Spoofing
Spoofing involves falsifying an identity, address, or other identifying information.
Examples include forged source IP addresses and impersonated network services.
On-Path Attack
An on-path attacker positions themselves between communicating parties to observe, redirect, or modify communications.
The term is also commonly associated with man-in-the-middle attacks.
DNS Attacks
DNS attacks target the infrastructure or processes used to resolve domain names.
They may redirect users, interrupt name resolution, or provide fraudulent responses.
Cache Poisoning
DNS cache poisoning introduces incorrect information into a resolver's cache.
A victim may be directed to an unintended destination even though the requested domain name appears correct.
Social Engineering Attacks
Social engineering manipulates people into taking actions or disclosing information that benefits an attacker.
| Attack | Defining characteristic |
|---|---|
| Phishing | Fraudulent messaging intended to deceive recipients |
| Spear phishing | Phishing tailored to a specific person or group |
| Whaling | Phishing targeting senior executives or similarly high-value individuals |
| Smishing | Phishing conducted through SMS or similar text messaging |
| Vishing | Phishing conducted through voice communications |
| Quishing | Phishing using QR codes |
| Impersonation | Pretending to be a trusted person or entity |
| Deepfake | Synthetic or manipulated media that convincingly imitates a person, voice, or event |
Exam scenario: A finance employee receives a convincing voice message that imitates the company's chief executive and requests an urgent transfer.
The scenario may involve vishing, impersonation, and deepfake technology simultaneously.
Indicators of Compromise
File Hash
A file hash may be compared against known malicious-file indicators.
A matching hash can support identification, but attackers may modify malware to produce a different hash.
IP Address
Connections to known malicious IP addresses may indicate suspicious network activity.
An IP address alone is not proof of compromise, particularly when infrastructure is shared or intelligence is outdated.
Domain
Connections to malicious or suspicious domains can indicate phishing, command-and-control activity, or other threats.
Malicious Processes
Unexpected processes, suspicious parent-child process relationships, or abnormal execution behavior may indicate malicious activity.
File System Artifacts
Unusual files, unexpected persistence-related changes, and modified system components may provide evidence of compromise.
Timestamps
File, event, and activity timestamps help establish when an incident may have occurred.
Timestamp anomalies may also suggest manipulation or inconsistent system clocks.
Log Manipulation
Deleted, disabled, altered, or unexpectedly missing security logs may indicate an attempt to conceal activity.
However, logging gaps may also result from legitimate operational failures.
Excessive Resource Consumption
Unexpected CPU, memory, storage, or network utilization may indicate cryptomining, malware, data processing, or denial-of-service activity.
Resource usage alone does not establish malicious intent.
Plaintext Strings
Readable strings within files, processes, or artifacts may reveal suspicious addresses, messages, configuration values, or malicious functionality.
Account Lockout
Repeated account lockouts may indicate password attacks or misuse of credentials.
Impossible Travel
Impossible travel refers to authentication activity appearing to occur from geographically distant locations within an implausibly short period.
VPNs, proxies, mobile networks, and geolocation errors can produce false positives.
Concurrent Sessions
Unexpected simultaneous sessions from distinct devices or locations may suggest credential theft or unauthorized account sharing.
They must be interpreted in light of normal application and user behavior.
Application Attacks
Injection
Injection occurs when untrusted input is interpreted as commands or instructions by an application component.
SQL injection is a common example involving unsafe construction of database queries.
Buffer Overflow
A buffer overflow occurs when software writes or handles data beyond the intended bounds of a memory buffer.
Depending on the implementation, consequences may include application crashes, data corruption, or code execution.
Replay
A replay attack reuses previously captured valid information, such as an authentication message or token, to obtain unauthorized results.
Privilege Escalation
Privilege escalation occurs when an attacker gains permissions beyond those originally available.
Vertical escalation involves gaining higher privileges. Horizontal escalation involves gaining unauthorized access to another identity's or peer's resources.
Forgery
Forgery involves creating or modifying information so it appears to originate from a legitimate source.
Examples include forged requests, documents, or transaction data.
Directory Traversal
Directory traversal exploits improper path handling to access files or directories outside the intended location.
The underlying weakness is inadequate restriction of accessible filesystem paths.
Credential Attacks
Password Spraying
Password spraying attempts a small number of commonly used passwords across many accounts.
It differs from repeatedly guessing numerous passwords against one account.
Brute Force
Brute-force attacks attempt many candidate credentials or secrets until a valid value is found.
They may target passwords, cryptographic material, or other security values.
User Enumeration
User enumeration identifies valid account names through observable application behavior.
For example, differing authentication responses may reveal whether a username exists.
Credential Replay
Credential replay involves reusing captured authentication material to attempt unauthorized access.
MFA Bypass
MFA bypass describes techniques that defeat, circumvent, or abuse multifactor authentication protections.
Examples may involve stolen authenticated sessions, deceptive approval requests, compromised recovery methods, or weaknesses in authentication workflows.
MFA substantially improves protection but does not eliminate every possible account-compromise method.
Objective 2.5 Review
Candidates should recognize attack patterns and match observable evidence to possible explanations.
| Scenario | Likely attack or indicator |
|---|---|
| Files become encrypted and a payment demand appears | Ransomware |
| Malware spreads autonomously between systems | Worm |
| A fraudulent QR code leads to a credential-harvesting page | Quishing |
| Many accounts receive attempts using the same weak password | Password spraying |
| A web application exposes files outside an intended directory | Directory traversal |
| A device communicates with a suspicious command-and-control domain | Potential indicator of compromise |
| An attacker reuses stolen authenticated session material | Session hijacking or replay, depending on behavior |
| A network service becomes unreachable under traffic from many distributed sources | DDoS |
2.6 — Summarize Threats and Vulnerabilities Associated with Artificial Intelligence (AI) Usage
AI systems introduce cybersecurity risks involving model behavior, training information, user inputs, connected tools, sensitive information, and automated decisions.
Security professionals must understand both deliberate attacks and unintended failures.
Model Manipulation
Model manipulation involves attempts to alter or influence an AI model's behavior, outputs, parameters, or associated processing in an unauthorized or deceptive manner.
An attacker may seek to cause incorrect classifications, unsafe responses, or behavior that differs from the system's intended design.
Poisoning
Poisoning involves introducing malicious or misleading information into data used for training, fine-tuning, evaluation, or retrieval.
For example, a compromised data source could introduce false information into an AI-supported decision process.
Poisoning differs from ordinary incorrect data when the contamination is intentionally designed to influence system behavior.
Prompt Injection
Prompt injection occurs when attacker-controlled content attempts to redirect an AI system away from its authorized instructions or intended task.
For example, an AI assistant summarizing a document might encounter embedded text instructing it to disregard its original task and disclose private information.
The malicious instructions are supplied through lower-trust content.
Important distinction: Prompt injection involves trying to cross an instruction-trust boundary. It is not simply an ordinary user asking a legitimate question.
Data Loss
AI-related data loss may occur when sensitive information is unintentionally exposed, copied, retained, transferred, or disclosed.
Potential causes include excessive tool permissions, insecure integrations, inappropriate use of confidential data, and malicious output manipulation.
Bias
AI bias occurs when a system produces systematically distorted or unfair outcomes due to training data, system design, evaluation methods, or deployment conditions.
Bias can undermine reliability, fairness, and security-related decision-making.
Explainability
Explainability concerns the ability to understand and communicate how an AI system reaches a result.
Limited explainability can make it difficult to investigate decisions, identify failures, evaluate model behavior, or establish accountability.
Explainability is not itself an attack. Its absence can create oversight and operational risks.
Hallucinations
AI hallucinations are outputs that contain fabricated, unsupported, or incorrect information presented as though it were reliable.
In cybersecurity, hallucinations may lead to incorrect incident conclusions, inaccurate vulnerability descriptions, or mistaken security recommendations.
A confident response is not evidence of correctness.
Jailbreaking
Jailbreaking involves attempts to bypass an AI system's intended behavioral restrictions or safety constraints.
Jailbreaking may involve specially crafted prompts or interactions intended to make the model behave outside its authorized limits.
Jailbreaking versus prompt injection: Jailbreaking often targets restrictions through direct interaction with the model; prompt injection commonly attempts to introduce controlling instructions through lower-trust content encountered during a task.
The two can overlap.
Evasion
AI evasion attacks attempt to cause an AI system to misinterpret, misclassify, or fail to recognize an input.
For example, adversarially modified content may cause a malicious message to be classified as benign.
Evasion targets the model's decision process, not necessarily its stored training data.
Privacy
AI systems may process personal, confidential, regulated, or proprietary information.
Privacy risks include unauthorized disclosure, excessive retention, inappropriate secondary use, and extraction of sensitive data from model interactions.
Privacy controls must consider the complete data lifecycle, including collection, processing, storage, sharing, and deletion.
Ethical Considerations
AI introduces ethical concerns involving fairness, consent, accountability, transparency, autonomy, and potential misuse.
Organizations may need governance processes that establish acceptable applications, oversight responsibilities, and consequences for harmful or inappropriate outcomes.
Ethical risks may overlap legal, privacy, and security requirements, but the concepts are not identical.
Session Hijacking
AI services frequently operate through authenticated web sessions and connected application workflows.
Session hijacking occurs when an unauthorized actor gains control of a valid authenticated session.
Within an AI application, this could expose conversation history, connected information, or actions permitted through the affected session.
Code Execution
Some AI systems interact with programming environments, automation platforms, or tools capable of executing code.
If a system incorrectly treats untrusted instructions as authorized actions, an attacker may induce unauthorized code execution.
The risk becomes more severe when the AI-connected environment has broad permissions or access to sensitive resources.
Exam scenario: An AI assistant processes an externally supplied document containing instructions that attempt to make the assistant invoke a connected tool and disclose confidential information.
The primary technique is prompt injection. Depending on the system's behavior, it may also lead to data loss or unauthorized tool execution.
AI Threat Comparison
| Concept | Primary concern |
|---|---|
| Model manipulation | Unauthorized alteration of model behavior |
| Poisoning | Malicious contamination of data used by an AI system |
| Prompt injection | Untrusted content attempting to redirect instructions |
| Data loss | Exposure or loss of protected information |
| Bias | Systematically distorted outcomes |
| Explainability | Difficulty understanding and auditing decisions |
| Hallucinations | Incorrect or fabricated outputs |
| Jailbreaking | Circumvention of intended model restrictions |
| Evasion | Manipulating inputs to defeat model detection or classification |
| Privacy | Improper handling of personal or confidential information |
| Ethical considerations | Responsible, fair, accountable deployment |
| Session hijacking | Unauthorized control of authenticated AI sessions |
| Code execution | Unauthorized execution through AI-connected capabilities |
Objective 2.6 Review
Candidates should distinguish deliberate adversarial techniques, such as poisoning and prompt injection, from reliability and governance concerns, such as hallucinations, bias, and explainability.
They should also understand how AI systems connected to external tools can increase the consequences of a compromised session or manipulated instruction.
Domain 2.0 — Examination Practice
These are original practice questions designed to reinforce Domain 2.0 concepts. They are not actual CompTIA examination questions.
Questions
1. A vulnerability has a CVSS score of 9.8, but the affected system is isolated and contains no business-critical information. Another vulnerability scores 8.1 and affects an actively targeted public application. What is the most appropriate conclusion?
A. The highest CVSS score must always be addressed first.
B. Neither vulnerability requires attention.
C. Prioritization should consider exploitation, exposure, and business impact.
D. CVSS scores identify threat actors.
2. Which identifier is used to reference an individual publicly disclosed vulnerability?
A. CVE
B. AAA
C. MFA
D. APT
3. A criminal organization steals customer records and threatens publication unless it receives payment. Which motivation best explains the demand?
A. Curiosity
B. Extortion
C. Ethical research
D. Availability
4. An attacker compromises a website regularly visited by employees of a particular government agency. What attack technique is illustrated?
A. Watering hole
B. Shoulder surfing
C. Password spraying
D. Key escrow
5. A company discovers an unauthorized cloud application being used to store internal documents. What concept best describes the situation?
A. Virtualization
B. Shadow IT
C. Certificate revocation
D. Key exchange
6. A developer embeds a database password directly into publicly accessible source code. What vulnerability is present?
A. Race condition
B. Hardcoded secret
C. Protocol downgrade
D. DNS cache poisoning
7. A malicious program spreads independently between vulnerable computers over a network. Which type of malware best matches this behavior?
A. Trojan
B. Worm
C. Logic bomb
D. Keylogger
8. Numerous employee accounts experience failed logins involving the same small set of passwords. Which attack is most likely?
A. Password spraying
B. Shoulder surfing
C. DNS spoofing
D. Directory traversal
9. An attacker sends a fraudulent message containing a QR code that directs victims to a fake login page. What is the attack called?
A. Vishing
B. Whaling
C. Quishing
D. Tailgating
10. A security system identifies successful authentication events from geographically distant locations within minutes. What indicator does this suggest?
A. Impossible travel
B. Fileless malware
C. Buffer overflow
D. Logic bomb
11. An application checks whether a resource can be accessed, but its state changes before the application uses it. What vulnerability is described?
A. Cache poisoning
B. TOC/TOU race condition
C. Brute-force attack
D. Shadow IT
12. An AI model is influenced by malicious information intentionally introduced into its training dataset. What threat does this demonstrate?
A. Evasion
B. Data poisoning
C. Session hijacking
D. Non-repudiation
13. An AI assistant encounters instructions hidden inside an untrusted web page that attempt to override its assigned task. What is the primary attack?
A. Prompt injection
B. Key escrow
C. Password spraying
D. Certificate forgery
14. A compromised administrative tool is used to perform unauthorized actions while appearing similar to legitimate system administration. Which technique is most relevant?
A. Living off the land
B. Full-disk encryption
C. Data masking
D. Physical skimming
15. An AI service generates a technically plausible but entirely fictitious vulnerability description. What AI limitation is illustrated?
A. Model explainability
B. Hallucination
C. Session hijacking
D. Training-data poisoning
16. A malicious browser extension collects authenticated session tokens. What is the most immediate security concern?
A. Power failure
B. Unauthorized session access
C. Hardware obsolescence
D. Cryptographic key length
17. An attacker creates unauthorized records in a DNS resolver cache so users are directed to an unintended server. Which attack is involved?
A. DNS cache poisoning
B. Network segmentation
C. Shoulder surfing
D. Brute force
18. A malicious update is distributed through a trusted third-party software provider. Which threat vector is most directly involved?
A. Physical entry
B. Supply chain
C. Bluetooth
D. Biometric spoofing
19. A previously dismissed employee's account remains active and is later used to access confidential information. Which weakness most directly enabled the event?
A. Stale credentials
B. Packet sniffing
C. Evasion
D. Protocol downgrade
20. A compromised AI agent uses a connected execution tool to perform actions outside its authorized task. Which AI-related risk best describes the outcome?
A. Code execution
B. Explainability
C. Bias
D. Data classification
Answers and Explanations
| Question | Answer | Explanation |
|---|---|---|
| 1 | C | Vulnerability prioritization includes exploitation evidence, exposure, and business context. |
| 2 | A | CVE provides standardized vulnerability identifiers. |
| 3 | B | Extortion involves coercion through threats or demands. |
| 4 | A | Watering-hole attacks target websites likely to be visited by intended victims. |
| 5 | B | Shadow IT operates outside approved organizational oversight. |
| 6 | B | Hardcoded secrets embed sensitive credentials in code or application artifacts. |
| 7 | B | Worms propagate independently between systems. |
| 8 | A | Password spraying uses a small set of passwords across multiple accounts. |
| 9 | C | Quishing is phishing involving QR codes. |
| 10 | A | Impossible travel describes implausibly distant authentication activity. |
| 11 | B | TOC/TOU vulnerabilities arise when state changes between validation and use. |
| 12 | B | Poisoning introduces malicious information into data influencing an AI system. |
| 13 | A | Prompt injection attempts to redirect an AI system through untrusted content. |
| 14 | A | Living-off-the-land activity misuses legitimate tools for malicious purposes. |
| 15 | B | Hallucinations are fabricated or unsupported AI-generated outputs. |
| 16 | B | Stolen session tokens may permit unauthorized session reuse. |
| 17 | A | DNS cache poisoning corrupts cached name-resolution information. |
| 18 | B | Trusted supplier compromise is a supply chain threat. |
| 19 | A | Stale credentials remain usable after their legitimate purpose ends. |
| 20 | A | Unauthorized actions through a connected execution environment illustrate the code-execution risk. |
Final Domain 2.0 Review
| Official objective | Core knowledge |
|---|---|
| 2.1 | Threat feeds, intelligence sources, likelihood, impact, threat intelligence life cycle, vulnerability scoring, CVSS, CVE, prioritization, and vulnerability types |
| 2.2 | Organized crime, terrorists, unskilled attackers, hacktivists, insiders, accidental actors, competitors, state-sponsored actors, motivations, resources, and sophistication |
| 2.3 | APTs and all message, image, attachment, browser, network, remote-access, endpoint, supply-chain, external-media, human, IoT, OT, physical, and signal-based vectors |
| 2.4 | Unsupported, unpatched, obsolete, and unmanaged systems; application and code weaknesses; credentials; rogue devices; shadow IT; wireless; LLMs; identity providers; mobile devices; public repositories and storage |
| 2.5 | Malware, physical attacks, network attacks, social engineering, indicators of compromise, application attacks, and credential attacks |
| 2.6 | Model manipulation, poisoning, prompt injection, data loss, bias, explainability, hallucinations, jailbreaking, evasion, privacy, ethics, session hijacking, and code execution |
Preparing for the Examination
Domain 2.0 places particular emphasis on scenario interpretation.
Candidates should be able to distinguish a threat actor from a threat vector, a vulnerability from evidence of exploitation, and a malicious technique from an observable indicator of compromise.
When analyzing a question, consider four issues:
- Who or what is involved? Identify the likely actor, system, or source.
- How does the activity occur? Determine the attack method or threat vector.
- What weakness makes it possible? Identify the vulnerability or attack surface.
- What evidence identifies the activity? Recognize the indicator and its limitations.
An effective examination answer depends on selecting the term that most precisely matches the stated evidence, rather than assuming every suspicious activity proves compromise.
Next Lesson: Part 4 — Security Architecture
Domain 3.0 covers architectural models, infrastructure protection, data security, resilience, business continuity, and recovery.
Official reference: CompTIA Security+ SY0-801 V8 Certification Exam Objectives, Document Version 2.0, Domain 2.0.
https://lecbyo.files.cmp.optimizely.com/download/77f3bd3223ac11f180820e495f189928
*Tech Little Brawta is an independent educational resource and is not affiliated with or endorsed by CompTIA. Security+ and CompTIA are trademarks of CompTIA, Inc.*
