Part 3 of 6 | Domain 2.0 | 24% of the Examination

Introduction

Cybersecurity threats can originate from organized criminal groups, foreign governments, employees, compromised suppliers, malicious software, and simple human mistakes.

Security professionals need to understand who poses a threat, how attacks occur, which weaknesses make systems vulnerable, and what evidence may indicate that an attack has taken place.

This lesson covers the six objectives in Domain 2.0 of the CompTIA Security+ SY0-801 examination:

  • 2.1: Explain characteristics of threats and vulnerabilities.
  • 2.2: Describe common threat actors and motivations.
  • 2.3: Describe threat vectors and sources.
  • 2.4: Explain types of vulnerabilities and attack surfaces.
  • 2.5: Given a scenario, analyze indicators of malicious activity.
  • 2.6: Summarize threats and vulnerabilities associated with artificial intelligence (AI) usage.

The goal is to understand each concept and recognize it in the scenario-based questions commonly associated with security certification examinations.


2.1 — Explain Characteristics of Threats and Vulnerabilities

Understanding Threats, Vulnerabilities, and Risk

A threat is something capable of causing harm to an organization, system, individual, or information asset.

A vulnerability is a weakness that could be exploited by a threat.

Risk represents the potential for an adverse event, considering factors such as likelihood and impact.

For example, a company operates an internet-facing application that contains a known security vulnerability.

The vulnerability is the weakness in the application. A criminal group seeking to exploit it represents a threat. The possibility that exploitation will cause unauthorized access, data theft, or service disruption represents risk.

A vulnerability does not necessarily mean an attack has occurred. An attack is an attempt to exploit or otherwise compromise a target.

Threat Feeds

Threat feeds provide information about potential or known security threats.

They may include malicious IP addresses, suspicious domains, malware hashes, known vulnerabilities, indicators of compromise, and observed attacker behavior.

A security information and event management (SIEM) platform can use this information to enrich security events and support investigations.

Threat feeds vary in accuracy, relevance, freshness, and reliability. A domain appearing in a threat feed is not necessarily sufficient evidence to conclude that every interaction with it is malicious.

Threat Intelligence Sources

Threat intelligence can originate from several sources.

SourceDescription
Open-source intelligence (OSINT)Publicly accessible information, including security reports and research
Commercial intelligenceInformation supplied by commercial threat intelligence providers
Government advisoriesAlerts and security guidance from national cybersecurity organizations
Information-sharing communitiesThreat intelligence exchanged between trusted organizations
Internal intelligenceInformation derived from the organization's own logs, alerts, investigations, and incidents
Industry groupsThreat information shared within a particular sector

Threat intelligence differs from raw threat data because intelligence includes analysis and context that helps decision-makers understand relevance and possible action.

Likelihood

Likelihood describes the probability or estimated chance that a particular threat event will occur.

Factors influencing likelihood include attacker interest, vulnerability exploitability, system exposure, existing safeguards, and evidence of active exploitation.

An internet-facing application with a widely exploited vulnerability may have greater likelihood of compromise than an isolated system with a difficult-to-exploit weakness.

Impact

Impact describes the consequences if a threat event occurs.

Potential consequences include financial loss, operational downtime, compromised information, regulatory penalties, reputational damage, and physical harm.

Risk assessment considers both likelihood and consequences rather than relying on technical severity alone.

Exam distinction: Likelihood concerns the chance of an event; impact concerns its consequences.

Threat Intelligence Life Cycle

Threat intelligence is developed through a recurring process.

StagePurpose
DirectionEstablish intelligence requirements and priorities
CollectionGather relevant data from selected sources
ProcessingNormalize, organize, and prepare collected information
AnalysisDetermine meaning, relevance, credibility, and implications
DisseminationDeliver useful intelligence to the intended audience
FeedbackEvaluate usefulness and refine future requirements

The cycle improves the quality and relevance of intelligence over time.

Understanding Vulnerabilities

Vulnerabilities may exist in software, hardware, applications, network configurations, identity systems, business processes, or human activities.

Examples include unsupported operating systems, missing security updates, insecure permissions, exposed credentials, and defective application logic.

Vulnerability Scoring: CVSS

The Common Vulnerability Scoring System (CVSS) provides a standardized framework for describing and scoring the severity of software vulnerabilities.

CVSS base scores commonly range from 0.0 to 10.0.

ScoreSeverity
0.0None
0.1–3.9Low
4.0–6.9Medium
7.0–8.9High
9.0–10.0Critical

CVSS considers characteristics such as exploit conditions and potential security impact. The precise metrics depend on the CVSS version.

A CVSS score indicates severity under the scoring model. It does not, by itself, determine the real-world risk to every organization.

Common Vulnerabilities and Exposures (CVE)

CVE is a standardized identification system for publicly disclosed cybersecurity vulnerabilities.

A CVE identifier has a format such as CVE-2026-12345, used here as an illustrative identifier rather than a claim about a real vulnerability.

CVE identifiers help different vendors, vulnerability scanners, advisories, and security teams refer to the same issue.

CVE versus CVSS:

  • CVE identifies a vulnerability.
  • CVSS describes its severity.

The National Vulnerability Database (NVD) is a separate resource that enriches published vulnerability information with additional analysis and metadata; it is not itself the CVE identifier system.

Vulnerability Prioritization

A security team may discover hundreds of vulnerabilities but cannot necessarily address all of them simultaneously.

Prioritization considers CVSS severity together with factors such as:

  • Whether attackers are actively exploiting the issue.
  • Whether the vulnerable system is exposed to the internet.
  • The business importance of the affected asset.
  • Potential impact on confidentiality, integrity, or availability.
  • Whether exploitation requires authentication or other special conditions.
  • Existing mitigating controls.
  • Availability and operational risk of remediation.

Exam scenario: Two vulnerabilities affect an organization. One has a higher CVSS score on an isolated test system. The other has a slightly lower score but is actively exploited on an internet-facing production server.

The second vulnerability may deserve higher operational priority because organizational exposure and exploitation evidence affect risk.

Objective 2.1 Review

Candidates should be able to distinguish threats, vulnerabilities, and risk; interpret CVSS and CVE references; understand threat intelligence sources and life cycles; and determine why contextual prioritization matters.


2.2 — Describe Common Threat Actors and Motivations

A threat actor is an individual, group, or organization capable of causing a cybersecurity incident.

Threat actors differ in their objectives, sophistication, funding, resources, and access to target systems.

Common Threat Actors

Crime Syndicates and Organized Crime

Organized cybercriminal groups conduct coordinated activities for financial benefit.

Their operations may include ransomware, data theft, payment fraud, extortion, and trafficking in stolen credentials.

Organized groups can be highly specialized, with different individuals or affiliates responsible for gaining access, developing malicious tools, negotiating payments, or laundering proceeds.

Terrorists

Terrorist organizations may use cyberattacks to spread fear, disrupt essential services, promote ideological objectives, or support broader campaigns.

Targets may include government systems, transportation, communications, or public infrastructure.

The defining factor is the actor's purpose, not a specific attack technique.

Unskilled Attackers

Unskilled attackers have limited technical ability and may depend on publicly available tools, prewritten scripts, or instructions created by others.

They may seek entertainment, recognition, experimentation, or opportunistic financial gain.

Limited sophistication does not mean they cannot cause substantial damage.

Hacktivists

Hacktivists use cyber activity to advance a political, social, or ideological cause.

Typical activities may include website defacement, information leaks, or disruptive denial-of-service attacks.

The primary distinguishing characteristic is the activist motivation rather than financial profit.

Insiders

Insiders are people with legitimate access to an organization's systems or information.

Examples include employees, administrators, contractors, and trusted business partners.

A malicious insider may misuse authorized access to steal information or sabotage systems.

An insider is not necessarily malicious, however. Accidental activity is a separate threat category.

Accidental or Unintentional Actors

Unintentional threat actors cause security incidents through mistakes, carelessness, or misunderstanding.

Examples include sending sensitive information to the wrong recipient, incorrectly configuring cloud permissions, or unintentionally disclosing protected material.

The security consequences can resemble those of intentional attacks, even though the motivation differs.

Competitors

Competitors may seek unauthorized access to trade secrets, product plans, financial data, customer lists, or other strategically valuable information.

The objective may be to gain a business advantage.

Ordinary lawful competitive research is not inherently a cybersecurity attack.

State-Sponsored Actors

State-sponsored actors receive support, direction, or resources from a government.

Their activities may involve espionage, strategic disruption, theft of intellectual property, influence operations, or preparation for conflict.

They may have significant resources, specialized capabilities, and long-term operational objectives.

Threat Actor Motivations

MotivationMeaningIllustrative scenario
FinancialObtaining money or monetary benefitCriminals steal payment information
InfluenceShaping decisions or perceptionsA campaign attempts to manipulate public opinion
Intellectual propertyObtaining proprietary knowledgeTheft of confidential product designs
NotorietySeeking attention or recognitionAn attacker publicizes a website compromise
EspionageSecretly obtaining sensitive intelligenceTheft of classified or strategic information
Fear or chaosCreating disruption or panicCoordinated attacks disrupt public services
ExtortionCoercing a victim for payment or concessionsThreatening to publish stolen records
General curiosityExploring systems without a defined harmful goalUnauthorized experimentation
RevengeRetaliating for a perceived grievanceA former employee damages company records
IdeologicalAdvancing a belief or causeAttack motivated by a social movement
PoliticalInfluencing political outcomesTargeting an election-related service
EthicalPursuing a perceived security or moral objectiveResearch intended to expose a weakness, potentially without authorization

Motivations can overlap. A criminal group might seek money through extortion, while a state-sponsored group might conduct espionage to acquire intellectual property.

An ethical intention does not automatically make unauthorized access lawful or acceptable.

Threat Actor Attributes

Internal Versus External

Internal actors possess legitimate organizational access or a trusted relationship with the organization.

External actors operate without that legitimate internal position.

An internal actor may already have knowledge of systems and business processes, while an external actor may first need to establish access.

Resources and Funding

Resources include money, equipment, personnel, infrastructure, specialist knowledge, and time.

An actor with significant funding may sustain long-term operations and develop specialized capabilities.

Sophistication and Capability

Sophistication concerns technical expertise, planning, and operational methods.

Capabilities concern what the actor can actually accomplish with available knowledge, tools, and access.

A highly sophisticated attacker may develop customized exploits, while a less sophisticated attacker may rely on commodity malware.

Exam scenario: A government-supported group spends several months attempting to collect sensitive aerospace research.

The most likely actor is state-sponsored, and the likely motivation is espionage or intellectual property acquisition.


2.3 — Describe Threat Vectors and Sources

A threat vector is the route or method through which a threat may reach a target.

A threat source is the person, system, organization, or condition from which a threat originates.

Threat vectors extend beyond email and malicious websites. They include devices, suppliers, physical access, wireless signals, identity systems, and trusted administrative tools.

Advanced Persistent Threat (APT)

An advanced persistent threat refers to a capable adversary or sustained intrusion campaign characterized by significant resources, planning, and long-term objectives.

An APT may seek continued access to sensitive systems, intelligence gathering, or strategic advantage.

An APT is not necessarily a single malware family. It describes a threat actor or sustained threat activity.

Message-Based Threat Vectors

Email

Email can deliver fraudulent messages, malicious links, attachments, and impersonation attempts.

A message appearing to originate from a trusted executive may attempt to induce a financial transfer or disclose credentials.

Short Message Service (SMS)

SMS provides a mobile messaging channel that attackers may misuse for fraudulent notices and malicious links.

SMS-based phishing is called smishing.

Rich Communication Services (RCS)

RCS is a modern messaging standard supporting richer communication features than traditional SMS.

As with other messaging systems, attackers may misuse it for impersonation, fraudulent links, or social engineering.

Instant Messaging

Instant messaging platforms may be exploited through compromised contacts, deceptive messages, malicious links, or unauthorized file sharing.

Collaboration Tools

Workplace collaboration services can be abused through fraudulent invitations, compromised accounts, malicious shared files, or deceptive conversations.

The appearance of an internal business communication may increase the credibility of a malicious message.

Image-Based Threat Vectors

Quick Response (QR) Codes

QR codes store machine-readable information, commonly including website addresses.

A malicious QR code may direct a person to a phishing website or other unsafe destination.

The term quishing describes phishing conducted through QR codes.

Embedded Content

Images or media content may contain links, embedded objects, or specially crafted data intended to exploit vulnerable software.

The risk depends on how the receiving application processes the content.

CAPTCHA

CAPTCHA technology attempts to distinguish human interaction from automated activity.

Attackers may imitate CAPTCHA interfaces to make malicious instructions or fraudulent websites appear legitimate.

CAPTCHA systems are not inherently malicious; the threat arises from deceptive use or exploitation.

Attachment-Based Threat Vectors

Embedded Macros

Macros automate functions within supported documents.

Malicious macros may be used to trigger unauthorized behavior when permitted by the document application and its security configuration.

Rich Text Format (RTF) Documents

RTF files support formatted text and can expose weaknesses in applications that process them.

A crafted document may exploit a vulnerable parser or related component.

Portable Document Format (PDF)

PDF files can contain complex document structures, links, forms, and other supported content.

Malicious PDFs may exploit software vulnerabilities or direct readers to fraudulent destinations.

A file extension alone does not establish whether an attachment is safe.

Browser-Based Threat Vectors

Browser Extensions

Extensions may receive permissions to interact with websites, browser content, or user information.

A malicious or compromised extension could misuse those permissions.

JavaScript

JavaScript is widely used for legitimate website functionality.

Attackers may exploit application weaknesses involving JavaScript, including cross-site scripting and other browser-based attacks.

Password Managers

Password managers protect and organize credentials but may become security targets.

Compromise of a manager, its account, endpoint, or browser integration can create significant exposure.

Cookies

Cookies store data associated with website interactions and sessions.

Some cookies contain session identifiers or other sensitive state.

Stolen session cookies may allow unauthorized access when a service accepts them as proof of an authenticated session.

Session Tokens

Session tokens represent an authenticated session or authorized interaction.

If a valid token is stolen and successfully reused, an attacker may gain access without knowing the user's password.

Network-Based Threat Vectors

Infrastructure Devices

Routers, switches, firewalls, and network appliances may be targeted through exposed management interfaces, vulnerable firmware, or compromised credentials.

Compromise can affect network traffic and access across multiple systems.

Virtualized Devices

Virtual machines, virtual appliances, virtual switches, and other virtual infrastructure components may contain security weaknesses.

Misconfigured virtual networking or compromised management systems can expose several workloads.

Session Keys

Session keys protect communications during an established session.

If an attacker obtains usable session-key material, the confidentiality or integrity of protected communications may be compromised, depending on the protocol and circumstances.

Remote Access Threat Vectors

Remote Desktop

Remote desktop technology permits interactive access to another computer.

Weak authentication, exposed services, or compromised accounts can turn remote access into an intrusion path.

Virtual Network Computing (VNC)

VNC provides remote graphical access.

Security depends on authentication, encryption, service configuration, and network exposure.

Virtual Private Network (VPN)

VPNs create protected network connections.

Compromised VPN credentials, vulnerabilities, or unsafe configurations may provide attackers with access to internal systems.

A VPN connection does not automatically make the connected identity trustworthy.

Endpoint-Based Threat Vectors

Mobile Devices

Smartphones can expose organizational data through malicious applications, phishing, operating system vulnerabilities, or device compromise.

Workstations

Workstations are common targets because they handle user activity, documents, browsers, and organizational credentials.

Servers

Servers may expose valuable data or business services. Vulnerabilities and compromised service accounts can have substantial consequences.

Tablets

Tablets share many mobile-device risks, including application permissions, operating system vulnerabilities, and unauthorized data access.

Trusted Devices

A previously trusted device may become compromised while retaining network access or organizational privileges.

Trust based only on prior approval can create security exposure.

Built-In Tools

Operating systems contain legitimate administrative and diagnostic utilities.

Attackers may abuse these built-in capabilities for unauthorized activities.

Living-off-the-Land Tools

Living-off-the-land attacks misuse existing legitimate utilities, services, and system capabilities rather than depending entirely on newly installed malicious software.

This can make malicious activity harder to distinguish from authorized administration.

Exam distinction: A legitimate utility is not inherently malicious. The context, intent, authorization, and observed behavior determine whether its use is suspicious.

Supply Chain-Based Threat Vectors

Third-Party Providers

Vendors may have access to organizational systems, information, or software development processes.

A provider compromise can introduce risk to the organizations that depend on it.

Managed Service Providers (MSPs)

MSPs frequently administer systems for several customers.

Compromise of a privileged MSP account or management platform can affect multiple client environments.

Logistics Providers

Logistics providers may handle equipment, deliveries, replacement parts, or sensitive business information.

Risks include device tampering, shipment diversion, and compromise during transport.

Software as a Service (SaaS) Providers

SaaS providers host applications and data on behalf of customers.

Provider compromise, insecure integrations, excessive permissions, or misconfigurations may affect customer information.

External Media-Based Threat Vectors

Malicious USB Devices

USB devices may carry malicious files, exploit device-handling weaknesses, or imitate other kinds of USB hardware.

The presence of a physical connector does not establish a device's identity or trustworthiness.

Human-Based Threat Vectors

Impersonation

An attacker pretends to be an authorized person, such as an executive, administrator, vendor, or support representative.

Contractors

Contractors may possess legitimate access but may work under different employment, management, or technical arrangements.

Their access can become a threat vector if compromised or improperly managed.

Visitors

Visitors may gain physical proximity to sensitive equipment, documents, or controlled locations.

Biometrics

Biometric systems use characteristics such as fingerprints or facial features.

Threats include presentation attacks, compromised biometric templates, and weaknesses in verification systems.

Watering Hole

A watering-hole attack compromises or imitates a website frequently visited by a particular group of potential victims.

Rather than contacting each target individually, the attacker positions the malicious content where intended victims are likely to encounter it.

Internet of Things (IoT)-Based Threat Vectors

IoT equipment includes network-connected devices that perform specialized functions.

Cameras

Compromised cameras can expose video, credentials, network access, or embedded computing capabilities.

Sensors

Sensors may collect measurements or control-related information.

Compromised sensors may provide misleading readings or become entry points into connected systems.

Printers

Network-connected printers may store documents, credentials, logs, or configuration information.

Weaknesses in their firmware or administration can expose sensitive resources.

Operational Technology (OT)-Based Threat Vectors

Operational technology monitors or controls physical and industrial processes.

Examples include industrial control systems, programmable logic controllers, and equipment used in manufacturing or utilities.

An OT compromise may affect physical safety, production reliability, or essential services.

Physical-Based Threat Vectors

Locks and Keys

Lost, stolen, duplicated, or improperly managed keys may allow unauthorized entry.

Access Vestibules

Access vestibules, sometimes called mantraps, regulate movement between controlled areas.

Failures in their physical or procedural controls may permit unauthorized access.

Access Passes

Access badges and passes identify individuals permitted to enter certain facilities.

Stolen, cloned, shared, or improperly deactivated passes may undermine access restrictions.

Signal-Based Threat Vectors

Bluetooth

Bluetooth supports short-range wireless communications.

Weak pairing, vulnerable implementations, or unauthorized connections can introduce security risks.

Radio Frequency (RF)

RF signals support many wireless technologies.

Threats may include interception, interference, spoofing, or unauthorized transmissions.

Near-Field Communications (NFC)

NFC supports very short-range communications, commonly for payment, access, and device interactions.

Security concerns may include unauthorized reading, relay attacks, or impersonation under applicable conditions.

Objective 2.3 Review

Candidates must recognize how threats can enter an environment through communication channels, endpoints, infrastructure, suppliers, human interactions, physical access, and wireless technologies.

A single incident may involve several vectors.

For example, a compromised supplier account might distribute a malicious attachment through a collaboration platform, combining supply chain, identity, messaging, and attachment-based exposure.


2.4 — Explain Types of Vulnerabilities and Attack Surfaces

An attack surface is the collection of interfaces, systems, identities, data, and access paths through which an attacker may attempt to interact with or compromise a target.

Reducing unnecessary exposure helps limit attack opportunities.

Unsupported Products

Unsupported products no longer receive the support or security maintenance required by their users.

A newly discovered vulnerability may remain unpatched if the vendor no longer provides updates.

Unsupported does not automatically mean compromised, but it increases management difficulty and long-term exposure.

Unpatched Systems

An unpatched system lacks one or more applicable updates.

Missing security patches can leave known vulnerabilities exploitable.

The significance depends on the vulnerability, system exposure, compensating controls, and availability of exploitation methods.

Obsolete Systems

Obsolete systems rely on outdated technology that may no longer meet operational or security requirements.

Obsolete and unsupported are related but distinct: technology may be old while still receiving support, or become unsupported even though it remains operationally necessary.

Unmanaged Systems

Unmanaged systems operate without adequate organizational visibility or security administration.

They may lack inventory records, approved configurations, security monitoring, or routine maintenance.

Unknown assets complicate vulnerability assessment and incident response.

Ports and Services

Network ports identify communication endpoints used by network services.

Unnecessary exposed services expand the potential attack surface.

A legitimately required open port is not automatically a vulnerability. Risk depends on the service, its configuration, access restrictions, and security posture.

Application Vulnerabilities

Applications may contain defects in business logic, data validation, authentication, memory handling, or dependencies.

Race Conditions

A race condition occurs when the outcome of an operation depends on the timing or ordering of concurrent actions.

An exploitable race condition may allow behavior that should not be permitted.

Time-of-Check and Time-of-Use (TOC/TOU)

A time-of-check/time-of-use vulnerability occurs when a condition is checked, but the relevant state changes before the associated action is completed.

For example, an application verifies that a resource is safe and later uses it without ensuring the original condition still holds.

An attacker may exploit the interval between verification and use.

Malicious Updates

An update package may be compromised or deliberately altered to include harmful functionality.

Because update mechanisms often have elevated trust, malicious updates can affect many systems.

Code Vulnerabilities

Hardcoded Secrets

Hardcoded secrets are credentials, passwords, API keys, or other sensitive values embedded directly in source code or application components.

If exposed through repositories, binaries, logs, or application distribution, they may provide unauthorized access.

Unsafe Exception Handling

Exception handling controls application behavior when errors occur.

Poor exception handling may expose stack traces, sensitive configuration values, internal paths, or other information useful to attackers.

It may also cause an application to fail insecurely.

Operating System-Based Vulnerabilities

Operating systems may contain vulnerabilities affecting memory handling, permissions, services, authentication, or kernel functionality.

A successful exploit could lead to unauthorized access, privilege escalation, or system compromise.

Virtualization Vulnerabilities

Virtualization introduces components such as hypervisors, virtual machines, virtual networking, and management interfaces.

Weak isolation, vulnerable hypervisors, or compromised management systems can threaten multiple hosted workloads.

Zero-Day Vulnerabilities

A zero-day vulnerability is a vulnerability for which defenders or the affected vendor have had no meaningful advance opportunity to develop and deploy a fix before exploitation or disclosure, depending on usage.

A zero-day exploit targets such a vulnerability.

The term does not mean the vulnerability has a CVSS score of zero.

Cryptographic Vulnerabilities

Cryptographic weaknesses can result from obsolete algorithms, poor key management, incorrect implementation, unsafe protocol configuration, or inadequate randomness.

Strong encryption algorithms do not compensate for exposed encryption keys.

Unmanaged or Stale Credentials

Stale credentials include accounts, passwords, tokens, or keys that remain usable after their original business purpose has ended.

Examples include accounts belonging to departed employees and forgotten service credentials.

They may provide attackers with access that is unlikely to attract immediate attention.

Rogue Devices

A rogue device is an unauthorized or malicious device connected to an environment.

Examples include an unauthorized wireless access point or an unfamiliar computer connected to a protected network.

Shadow IT

Shadow IT refers to technology adopted or operated outside approved organizational oversight.

Employees might store business files in an unapproved cloud application or use an unsanctioned service to process sensitive information.

The primary problem is lack of visibility, governance, and consistent protection.

Wireless and Low-Powered Communications

Wireless technologies may suffer from weak authentication, insufficient encryption, vulnerable implementations, or signal-based attacks.

Low-powered devices can also have limited processing resources and security-maintenance capabilities.

Large Language Models (LLMs)

LLMs introduce new attack surfaces involving prompts, training or retrieval data, external tools, model outputs, and sensitive information.

Examples include prompt injection, disclosure of private information, and excessive authority granted to AI-connected tools.

Objective 2.6 explores AI-related risks in more detail.

Identity Providers

Identity providers manage authentication and related identity services.

Compromise or misconfiguration may affect numerous connected applications through federation, single sign-on, or identity synchronization.

Mobile Devices

Mobile devices introduce risks involving insecure applications, lost devices, compromised credentials, outdated software, and sensitive data stored locally or accessed remotely.

Misconfiguration

A misconfiguration occurs when a system is set up in an insecure or unintended way.

Examples include excessive permissions, default credentials, exposed administrative interfaces, and incorrectly configured access controls.

A system can be fully patched and still be insecure because of its configuration.

Public Repositories

Public code repositories may expose sensitive data when developers accidentally commit secrets, private configuration files, internal documentation, or confidential source code.

Public accessibility is not inherently a vulnerability. The risk depends on the information exposed.

Public Object Storage

Cloud object storage may unintentionally expose data through overly permissive access policies or publicly accessible objects.

An organization may experience a data disclosure without a software exploit if stored information is configured for unintended public access.

Objective 2.4 Review

The examination may describe a system weakness and ask candidates to identify its category.

A forgotten employee account suggests stale credentials. An unapproved cloud service suggests shadow IT. An exposed storage bucket suggests misconfiguration or public object storage. An application whose authorization state changes between validation and execution suggests a TOC/TOU race condition.


2.5 — Given a Scenario, Analyze Indicators of Malicious Activity

Malicious activity can produce evidence in system logs, network traffic, files, processes, authentication records, and user reports.

An indicator of compromise (IOC) is observable information that may suggest unauthorized or malicious activity.

Not every indicator proves a compromise. Evidence must be interpreted in context.

Malware Attacks

Malware is software or code designed to perform unauthorized, harmful, deceptive, or otherwise malicious actions.

Ransomware

Ransomware attempts to deny access to information or systems, commonly through encryption, and demands payment or another concession.

Modern ransomware attacks may also involve theft of information and threats to publish it.

Typical indicators: Unexpected mass file encryption, ransom notes, inaccessible files, and unusual file modifications.

Trojan

A Trojan is malicious software that disguises itself as legitimate or desirable software.

A Trojan depends on deceptive presentation or delivery; it does not inherently self-replicate.

Worm

A worm is malware capable of spreading between systems, often through network-accessible vulnerabilities or other propagation mechanisms.

Worm activity may cause rapid infection and substantial network traffic.

Spyware

Spyware secretly gathers information about users, devices, or activity.

It may collect browsing information, credentials, or other sensitive data.

Adware

Adware displays advertisements, sometimes in intrusive or deceptive ways.

Not all advertising-supported software is malware. Adware becomes a security concern when it engages in unwanted, deceptive, or harmful behavior.

Virus

A computer virus attaches to or infects another file, program, or component and replicates when the infected host is activated.

Virus versus worm: A virus normally requires a host component and execution conditions; a worm is designed for independent propagation.

Rootkit

A rootkit hides malicious activity or provides concealed privileged access.

It may manipulate operating system behavior to make files, processes, or other evidence difficult to detect.

Keylogger

A keylogger records keyboard input.

Malicious keyloggers may capture credentials, messages, and confidential information.

Logic Bomb

A logic bomb is malicious functionality designed to activate when a predefined condition occurs.

For example, harmful code might be triggered by a particular date or system event.

Fileless Malware

Fileless malware relies heavily on memory, legitimate system processes, or built-in capabilities rather than conventional malicious executable files stored on disk.

It may leave fewer traditional file artifacts, but it can still generate process, memory, network, or log evidence.

Physical Attacks

AttackDescription
TailgatingAn unauthorized person follows an authorized person into a restricted area
Shoulder surfingObserving sensitive information over someone's shoulder or from nearby
SkimmingIllegitimately collecting payment-card or similar data using a compromised reader
Forced entryGaining access by physically defeating barriers or access restrictions

These attacks exploit physical access and human behavior rather than necessarily requiring software vulnerabilities.

Network Attacks

Distributed Denial of Service (DDoS)

A DDoS attack uses multiple sources to overwhelm a target's network, systems, or application resources.

The primary objective is often to disrupt availability.

Protocol Downgrade

A protocol downgrade attack attempts to force communicating parties to use an older or weaker security protocol or mode.

The resulting connection may provide weaker confidentiality or integrity protections.

Rogue Network Components

A rogue network device is an unauthorized component, such as an access point, that may intercept communications or provide an unintended connection path.

Sniffing

Sniffing involves capturing or observing network traffic.

Traffic analysis may be legitimate during authorized troubleshooting. Malicious sniffing seeks unauthorized information.

Spoofing

Spoofing involves falsifying an identity, address, or other identifying information.

Examples include forged source IP addresses and impersonated network services.

On-Path Attack

An on-path attacker positions themselves between communicating parties to observe, redirect, or modify communications.

The term is also commonly associated with man-in-the-middle attacks.

DNS Attacks

DNS attacks target the infrastructure or processes used to resolve domain names.

They may redirect users, interrupt name resolution, or provide fraudulent responses.

Cache Poisoning

DNS cache poisoning introduces incorrect information into a resolver's cache.

A victim may be directed to an unintended destination even though the requested domain name appears correct.

Social Engineering Attacks

Social engineering manipulates people into taking actions or disclosing information that benefits an attacker.

AttackDefining characteristic
PhishingFraudulent messaging intended to deceive recipients
Spear phishingPhishing tailored to a specific person or group
WhalingPhishing targeting senior executives or similarly high-value individuals
SmishingPhishing conducted through SMS or similar text messaging
VishingPhishing conducted through voice communications
QuishingPhishing using QR codes
ImpersonationPretending to be a trusted person or entity
DeepfakeSynthetic or manipulated media that convincingly imitates a person, voice, or event

Exam scenario: A finance employee receives a convincing voice message that imitates the company's chief executive and requests an urgent transfer.

The scenario may involve vishing, impersonation, and deepfake technology simultaneously.

Indicators of Compromise

File Hash

A file hash may be compared against known malicious-file indicators.

A matching hash can support identification, but attackers may modify malware to produce a different hash.

IP Address

Connections to known malicious IP addresses may indicate suspicious network activity.

An IP address alone is not proof of compromise, particularly when infrastructure is shared or intelligence is outdated.

Domain

Connections to malicious or suspicious domains can indicate phishing, command-and-control activity, or other threats.

Malicious Processes

Unexpected processes, suspicious parent-child process relationships, or abnormal execution behavior may indicate malicious activity.

File System Artifacts

Unusual files, unexpected persistence-related changes, and modified system components may provide evidence of compromise.

Timestamps

File, event, and activity timestamps help establish when an incident may have occurred.

Timestamp anomalies may also suggest manipulation or inconsistent system clocks.

Log Manipulation

Deleted, disabled, altered, or unexpectedly missing security logs may indicate an attempt to conceal activity.

However, logging gaps may also result from legitimate operational failures.

Excessive Resource Consumption

Unexpected CPU, memory, storage, or network utilization may indicate cryptomining, malware, data processing, or denial-of-service activity.

Resource usage alone does not establish malicious intent.

Plaintext Strings

Readable strings within files, processes, or artifacts may reveal suspicious addresses, messages, configuration values, or malicious functionality.

Account Lockout

Repeated account lockouts may indicate password attacks or misuse of credentials.

Impossible Travel

Impossible travel refers to authentication activity appearing to occur from geographically distant locations within an implausibly short period.

VPNs, proxies, mobile networks, and geolocation errors can produce false positives.

Concurrent Sessions

Unexpected simultaneous sessions from distinct devices or locations may suggest credential theft or unauthorized account sharing.

They must be interpreted in light of normal application and user behavior.

Application Attacks

Injection

Injection occurs when untrusted input is interpreted as commands or instructions by an application component.

SQL injection is a common example involving unsafe construction of database queries.

Buffer Overflow

A buffer overflow occurs when software writes or handles data beyond the intended bounds of a memory buffer.

Depending on the implementation, consequences may include application crashes, data corruption, or code execution.

Replay

A replay attack reuses previously captured valid information, such as an authentication message or token, to obtain unauthorized results.

Privilege Escalation

Privilege escalation occurs when an attacker gains permissions beyond those originally available.

Vertical escalation involves gaining higher privileges. Horizontal escalation involves gaining unauthorized access to another identity's or peer's resources.

Forgery

Forgery involves creating or modifying information so it appears to originate from a legitimate source.

Examples include forged requests, documents, or transaction data.

Directory Traversal

Directory traversal exploits improper path handling to access files or directories outside the intended location.

The underlying weakness is inadequate restriction of accessible filesystem paths.

Credential Attacks

Password Spraying

Password spraying attempts a small number of commonly used passwords across many accounts.

It differs from repeatedly guessing numerous passwords against one account.

Brute Force

Brute-force attacks attempt many candidate credentials or secrets until a valid value is found.

They may target passwords, cryptographic material, or other security values.

User Enumeration

User enumeration identifies valid account names through observable application behavior.

For example, differing authentication responses may reveal whether a username exists.

Credential Replay

Credential replay involves reusing captured authentication material to attempt unauthorized access.

MFA Bypass

MFA bypass describes techniques that defeat, circumvent, or abuse multifactor authentication protections.

Examples may involve stolen authenticated sessions, deceptive approval requests, compromised recovery methods, or weaknesses in authentication workflows.

MFA substantially improves protection but does not eliminate every possible account-compromise method.

Objective 2.5 Review

Candidates should recognize attack patterns and match observable evidence to possible explanations.

ScenarioLikely attack or indicator
Files become encrypted and a payment demand appearsRansomware
Malware spreads autonomously between systemsWorm
A fraudulent QR code leads to a credential-harvesting pageQuishing
Many accounts receive attempts using the same weak passwordPassword spraying
A web application exposes files outside an intended directoryDirectory traversal
A device communicates with a suspicious command-and-control domainPotential indicator of compromise
An attacker reuses stolen authenticated session materialSession hijacking or replay, depending on behavior
A network service becomes unreachable under traffic from many distributed sourcesDDoS

2.6 — Summarize Threats and Vulnerabilities Associated with Artificial Intelligence (AI) Usage

AI systems introduce cybersecurity risks involving model behavior, training information, user inputs, connected tools, sensitive information, and automated decisions.

Security professionals must understand both deliberate attacks and unintended failures.

Model Manipulation

Model manipulation involves attempts to alter or influence an AI model's behavior, outputs, parameters, or associated processing in an unauthorized or deceptive manner.

An attacker may seek to cause incorrect classifications, unsafe responses, or behavior that differs from the system's intended design.

Poisoning

Poisoning involves introducing malicious or misleading information into data used for training, fine-tuning, evaluation, or retrieval.

For example, a compromised data source could introduce false information into an AI-supported decision process.

Poisoning differs from ordinary incorrect data when the contamination is intentionally designed to influence system behavior.

Prompt Injection

Prompt injection occurs when attacker-controlled content attempts to redirect an AI system away from its authorized instructions or intended task.

For example, an AI assistant summarizing a document might encounter embedded text instructing it to disregard its original task and disclose private information.

The malicious instructions are supplied through lower-trust content.

Important distinction: Prompt injection involves trying to cross an instruction-trust boundary. It is not simply an ordinary user asking a legitimate question.

Data Loss

AI-related data loss may occur when sensitive information is unintentionally exposed, copied, retained, transferred, or disclosed.

Potential causes include excessive tool permissions, insecure integrations, inappropriate use of confidential data, and malicious output manipulation.

Bias

AI bias occurs when a system produces systematically distorted or unfair outcomes due to training data, system design, evaluation methods, or deployment conditions.

Bias can undermine reliability, fairness, and security-related decision-making.

Explainability

Explainability concerns the ability to understand and communicate how an AI system reaches a result.

Limited explainability can make it difficult to investigate decisions, identify failures, evaluate model behavior, or establish accountability.

Explainability is not itself an attack. Its absence can create oversight and operational risks.

Hallucinations

AI hallucinations are outputs that contain fabricated, unsupported, or incorrect information presented as though it were reliable.

In cybersecurity, hallucinations may lead to incorrect incident conclusions, inaccurate vulnerability descriptions, or mistaken security recommendations.

A confident response is not evidence of correctness.

Jailbreaking

Jailbreaking involves attempts to bypass an AI system's intended behavioral restrictions or safety constraints.

Jailbreaking may involve specially crafted prompts or interactions intended to make the model behave outside its authorized limits.

Jailbreaking versus prompt injection: Jailbreaking often targets restrictions through direct interaction with the model; prompt injection commonly attempts to introduce controlling instructions through lower-trust content encountered during a task.

The two can overlap.

Evasion

AI evasion attacks attempt to cause an AI system to misinterpret, misclassify, or fail to recognize an input.

For example, adversarially modified content may cause a malicious message to be classified as benign.

Evasion targets the model's decision process, not necessarily its stored training data.

Privacy

AI systems may process personal, confidential, regulated, or proprietary information.

Privacy risks include unauthorized disclosure, excessive retention, inappropriate secondary use, and extraction of sensitive data from model interactions.

Privacy controls must consider the complete data lifecycle, including collection, processing, storage, sharing, and deletion.

Ethical Considerations

AI introduces ethical concerns involving fairness, consent, accountability, transparency, autonomy, and potential misuse.

Organizations may need governance processes that establish acceptable applications, oversight responsibilities, and consequences for harmful or inappropriate outcomes.

Ethical risks may overlap legal, privacy, and security requirements, but the concepts are not identical.

Session Hijacking

AI services frequently operate through authenticated web sessions and connected application workflows.

Session hijacking occurs when an unauthorized actor gains control of a valid authenticated session.

Within an AI application, this could expose conversation history, connected information, or actions permitted through the affected session.

Code Execution

Some AI systems interact with programming environments, automation platforms, or tools capable of executing code.

If a system incorrectly treats untrusted instructions as authorized actions, an attacker may induce unauthorized code execution.

The risk becomes more severe when the AI-connected environment has broad permissions or access to sensitive resources.

Exam scenario: An AI assistant processes an externally supplied document containing instructions that attempt to make the assistant invoke a connected tool and disclose confidential information.

The primary technique is prompt injection. Depending on the system's behavior, it may also lead to data loss or unauthorized tool execution.

AI Threat Comparison

ConceptPrimary concern
Model manipulationUnauthorized alteration of model behavior
PoisoningMalicious contamination of data used by an AI system
Prompt injectionUntrusted content attempting to redirect instructions
Data lossExposure or loss of protected information
BiasSystematically distorted outcomes
ExplainabilityDifficulty understanding and auditing decisions
HallucinationsIncorrect or fabricated outputs
JailbreakingCircumvention of intended model restrictions
EvasionManipulating inputs to defeat model detection or classification
PrivacyImproper handling of personal or confidential information
Ethical considerationsResponsible, fair, accountable deployment
Session hijackingUnauthorized control of authenticated AI sessions
Code executionUnauthorized execution through AI-connected capabilities

Objective 2.6 Review

Candidates should distinguish deliberate adversarial techniques, such as poisoning and prompt injection, from reliability and governance concerns, such as hallucinations, bias, and explainability.

They should also understand how AI systems connected to external tools can increase the consequences of a compromised session or manipulated instruction.


Domain 2.0 — Examination Practice

These are original practice questions designed to reinforce Domain 2.0 concepts. They are not actual CompTIA examination questions.

Questions

1. A vulnerability has a CVSS score of 9.8, but the affected system is isolated and contains no business-critical information. Another vulnerability scores 8.1 and affects an actively targeted public application. What is the most appropriate conclusion?

A. The highest CVSS score must always be addressed first.
B. Neither vulnerability requires attention.
C. Prioritization should consider exploitation, exposure, and business impact.
D. CVSS scores identify threat actors.

2. Which identifier is used to reference an individual publicly disclosed vulnerability?

A. CVE
B. AAA
C. MFA
D. APT

3. A criminal organization steals customer records and threatens publication unless it receives payment. Which motivation best explains the demand?

A. Curiosity
B. Extortion
C. Ethical research
D. Availability

4. An attacker compromises a website regularly visited by employees of a particular government agency. What attack technique is illustrated?

A. Watering hole
B. Shoulder surfing
C. Password spraying
D. Key escrow

5. A company discovers an unauthorized cloud application being used to store internal documents. What concept best describes the situation?

A. Virtualization
B. Shadow IT
C. Certificate revocation
D. Key exchange

6. A developer embeds a database password directly into publicly accessible source code. What vulnerability is present?

A. Race condition
B. Hardcoded secret
C. Protocol downgrade
D. DNS cache poisoning

7. A malicious program spreads independently between vulnerable computers over a network. Which type of malware best matches this behavior?

A. Trojan
B. Worm
C. Logic bomb
D. Keylogger

8. Numerous employee accounts experience failed logins involving the same small set of passwords. Which attack is most likely?

A. Password spraying
B. Shoulder surfing
C. DNS spoofing
D. Directory traversal

9. An attacker sends a fraudulent message containing a QR code that directs victims to a fake login page. What is the attack called?

A. Vishing
B. Whaling
C. Quishing
D. Tailgating

10. A security system identifies successful authentication events from geographically distant locations within minutes. What indicator does this suggest?

A. Impossible travel
B. Fileless malware
C. Buffer overflow
D. Logic bomb

11. An application checks whether a resource can be accessed, but its state changes before the application uses it. What vulnerability is described?

A. Cache poisoning
B. TOC/TOU race condition
C. Brute-force attack
D. Shadow IT

12. An AI model is influenced by malicious information intentionally introduced into its training dataset. What threat does this demonstrate?

A. Evasion
B. Data poisoning
C. Session hijacking
D. Non-repudiation

13. An AI assistant encounters instructions hidden inside an untrusted web page that attempt to override its assigned task. What is the primary attack?

A. Prompt injection
B. Key escrow
C. Password spraying
D. Certificate forgery

14. A compromised administrative tool is used to perform unauthorized actions while appearing similar to legitimate system administration. Which technique is most relevant?

A. Living off the land
B. Full-disk encryption
C. Data masking
D. Physical skimming

15. An AI service generates a technically plausible but entirely fictitious vulnerability description. What AI limitation is illustrated?

A. Model explainability
B. Hallucination
C. Session hijacking
D. Training-data poisoning

16. A malicious browser extension collects authenticated session tokens. What is the most immediate security concern?

A. Power failure
B. Unauthorized session access
C. Hardware obsolescence
D. Cryptographic key length

17. An attacker creates unauthorized records in a DNS resolver cache so users are directed to an unintended server. Which attack is involved?

A. DNS cache poisoning
B. Network segmentation
C. Shoulder surfing
D. Brute force

18. A malicious update is distributed through a trusted third-party software provider. Which threat vector is most directly involved?

A. Physical entry
B. Supply chain
C. Bluetooth
D. Biometric spoofing

19. A previously dismissed employee's account remains active and is later used to access confidential information. Which weakness most directly enabled the event?

A. Stale credentials
B. Packet sniffing
C. Evasion
D. Protocol downgrade

20. A compromised AI agent uses a connected execution tool to perform actions outside its authorized task. Which AI-related risk best describes the outcome?

A. Code execution
B. Explainability
C. Bias
D. Data classification

Answers and Explanations

QuestionAnswerExplanation
1CVulnerability prioritization includes exploitation evidence, exposure, and business context.
2ACVE provides standardized vulnerability identifiers.
3BExtortion involves coercion through threats or demands.
4AWatering-hole attacks target websites likely to be visited by intended victims.
5BShadow IT operates outside approved organizational oversight.
6BHardcoded secrets embed sensitive credentials in code or application artifacts.
7BWorms propagate independently between systems.
8APassword spraying uses a small set of passwords across multiple accounts.
9CQuishing is phishing involving QR codes.
10AImpossible travel describes implausibly distant authentication activity.
11BTOC/TOU vulnerabilities arise when state changes between validation and use.
12BPoisoning introduces malicious information into data influencing an AI system.
13APrompt injection attempts to redirect an AI system through untrusted content.
14ALiving-off-the-land activity misuses legitimate tools for malicious purposes.
15BHallucinations are fabricated or unsupported AI-generated outputs.
16BStolen session tokens may permit unauthorized session reuse.
17ADNS cache poisoning corrupts cached name-resolution information.
18BTrusted supplier compromise is a supply chain threat.
19AStale credentials remain usable after their legitimate purpose ends.
20AUnauthorized actions through a connected execution environment illustrate the code-execution risk.

Final Domain 2.0 Review

Official objectiveCore knowledge
2.1Threat feeds, intelligence sources, likelihood, impact, threat intelligence life cycle, vulnerability scoring, CVSS, CVE, prioritization, and vulnerability types
2.2Organized crime, terrorists, unskilled attackers, hacktivists, insiders, accidental actors, competitors, state-sponsored actors, motivations, resources, and sophistication
2.3APTs and all message, image, attachment, browser, network, remote-access, endpoint, supply-chain, external-media, human, IoT, OT, physical, and signal-based vectors
2.4Unsupported, unpatched, obsolete, and unmanaged systems; application and code weaknesses; credentials; rogue devices; shadow IT; wireless; LLMs; identity providers; mobile devices; public repositories and storage
2.5Malware, physical attacks, network attacks, social engineering, indicators of compromise, application attacks, and credential attacks
2.6Model manipulation, poisoning, prompt injection, data loss, bias, explainability, hallucinations, jailbreaking, evasion, privacy, ethics, session hijacking, and code execution

Preparing for the Examination

Domain 2.0 places particular emphasis on scenario interpretation.

Candidates should be able to distinguish a threat actor from a threat vector, a vulnerability from evidence of exploitation, and a malicious technique from an observable indicator of compromise.

When analyzing a question, consider four issues:

  1. Who or what is involved? Identify the likely actor, system, or source.
  2. How does the activity occur? Determine the attack method or threat vector.
  3. What weakness makes it possible? Identify the vulnerability or attack surface.
  4. What evidence identifies the activity? Recognize the indicator and its limitations.

An effective examination answer depends on selecting the term that most precisely matches the stated evidence, rather than assuming every suspicious activity proves compromise.


Next Lesson: Part 4 — Security Architecture

Domain 3.0 covers architectural models, infrastructure protection, data security, resilience, business continuity, and recovery.

Official reference: CompTIA Security+ SY0-801 V8 Certification Exam Objectives, Document Version 2.0, Domain 2.0.

https://lecbyo.files.cmp.optimizely.com/download/77f3bd3223ac11f180820e495f189928

*Tech Little Brawta is an independent educational resource and is not affiliated with or endorsed by CompTIA. Security+ and CompTIA are trademarks of CompTIA, Inc.*