CompTIA Security+ SY0-701 Threat Vectors and Attack Surfaces Practice Test
Topic 06 focuses on Threat Vectors and Attack Surfaces for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
Which term describes delivery of malicious links, attachments, requests, or social-engineering content through email?
Correct Answer: D
Correct Answer
Answer D is correct because Email-based vector means delivery of malicious links, attachments, requests, or social-engineering content through email.
Incorrect Answers
Answer A is incorrect because Supply-chain vector would fit a different scenario. Supply-chain vector refers to compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source.
Answer B is incorrect because File-based vector represents a different security function. File-based vector refers to use of a malicious or weaponized file as the initial delivery mechanism.
Answer C is incorrect because Watering-hole attack addresses a different requirement. Watering-hole attack refers to compromise of a site or resource that the intended victims are known to visit.
Question 2
To target mobile users through messages that appear urgent or familiar, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because SMS-based vector means delivery of malicious links or deceptive requests through text messaging.
Incorrect Answers
Answer A is incorrect because Unsecured wireless network would fit a different scenario. Unsecured wireless network refers to a wireless environment with weak or absent security controls.
Answer C is incorrect because Removable-device vector addresses a different requirement. Removable-device vector refers to use of USB or other removable media to introduce malware or move data.
Answer D is incorrect because Brand impersonation addresses a different security requirement. Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users.
Question 3
Which term describes use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts?
Correct Answer: A
Correct Answer
Answer A is correct because Instant-messaging vector means use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts.
Incorrect Answers
Answer B is incorrect because Impersonation represents a different security function. Impersonation refers to pretending to be a trusted person, organization, or system.
Answer C is incorrect because Default credentials would fit a different scenario. Default credentials refers to vendor-supplied or predictable usernames and passwords that have not been changed.
Answer D is incorrect because SMS-based vector addresses a different requirement. SMS-based vector refers to delivery of malicious links or deceptive requests through text messaging.
Question 4
To trigger compromise when a user opens or processes a file, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because File-based vector means use of a malicious or weaponized file as the initial delivery mechanism.
Incorrect Answers
Answer A is incorrect because Brand impersonation would fit a different scenario. Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users.
Answer B is incorrect because Smishing addresses a different requirement. Smishing refers to phishing delivered through SMS or text messaging.
Answer C is incorrect because SMS-based vector addresses a different security requirement. SMS-based vector refers to delivery of malicious links or deceptive requests through text messaging.
Question 5
Which term describes use of spoken interaction to deceive a person into revealing information or taking an unsafe action?
Correct Answer: A
Correct Answer
Answer A is correct because Voice-call vector means use of spoken interaction to deceive a person into revealing information or taking an unsafe action.
Incorrect Answers
Answer B is incorrect because Phishing represents a different security function. Phishing refers to a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action.
Answer C is incorrect because Brand impersonation would fit a different scenario. Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users.
Answer D is incorrect because Vishing addresses a different requirement. Vishing refers to voice-based phishing performed through phone calls or other voice channels.
Question 6
To cross network boundaries through portable storage, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Removable-device vector means use of USB or other removable media to introduce malware or move data.
Incorrect Answers
Answer A is incorrect because File-based vector would fit a different scenario. File-based vector refers to use of a malicious or weaponized file as the initial delivery mechanism.
Answer B is incorrect because Open service port addresses a different security requirement. Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.
Answer D is incorrect because Business email compromise addresses a different requirement. Business email compromise refers to fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions.
Question 7
Which term describes software with an exploitable flaw that creates an attack surface?
Correct Answer: D
Correct Answer
Answer D is correct because Vulnerable software means software with an exploitable flaw that creates an attack surface.
Incorrect Answers
Answer A is incorrect because Voice-call vector would fit a different scenario. Voice-call vector refers to use of spoken interaction to deceive a person into revealing information or taking an unsafe action.
Answer B is incorrect because Business email compromise addresses a different requirement. Business email compromise refers to fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions.
Answer C is incorrect because Disinformation represents a different security function. Disinformation refers to false information deliberately created or spread to deceive.
Question 8
To exploit known weaknesses that cannot be remediated through normal updates, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Unsupported system means a system or application that no longer receives security fixes or vendor support.
Incorrect Answers
Answer A is incorrect because Brand impersonation would fit a different scenario. Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users.
Answer C is incorrect because Phishing addresses a different requirement. Phishing refers to a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action.
Answer D is incorrect because Misinformation addresses a different security requirement. Misinformation refers to false information that is shared without necessarily intending to deceive.
Question 9
What is a wireless environment with weak or absent security controls?
Correct Answer: B
Correct Answer
Answer B is correct because Unsecured wireless network means a wireless environment with weak or absent security controls.
Incorrect Answers
Answer A is incorrect because Pretexting addresses a different requirement. Pretexting refers to social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request.
Answer C is incorrect because Typosquatting represents a different security function. Typosquatting refers to registration or use of look-alike domain names based on common spelling mistakes.
Answer D is incorrect because Open service port would fit a different scenario. Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.
Question 10
To expand the externally reachable attack surface, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Open service port means a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.
Incorrect Answers
Answer B is incorrect because Phishing addresses a different security requirement. Phishing refers to a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action.
Answer C is incorrect because Default credentials would fit a different scenario. Default credentials refers to vendor-supplied or predictable usernames and passwords that have not been changed.
Answer D is incorrect because Email-based vector addresses a different requirement. Email-based vector refers to delivery of malicious links, attachments, requests, or social-engineering content through email.
Question 11
Which term describes vendor-supplied or predictable usernames and passwords that have not been changed?
Correct Answer: A
Correct Answer
Answer A is correct because Default credentials means vendor-supplied or predictable usernames and passwords that have not been changed.
Incorrect Answers
Answer B is incorrect because Disinformation addresses a different requirement. Disinformation refers to false information deliberately created or spread to deceive.
Answer C is incorrect because Instant-messaging vector represents a different security function. Instant-messaging vector refers to use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts.
Answer D is incorrect because Phishing would fit a different scenario. Phishing refers to a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action.
Question 12
To reach a target indirectly by abusing trusted third parties or dependencies, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Supply-chain vector means compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source.
Incorrect Answers
Answer A is incorrect because Vishing would fit a different scenario. Vishing refers to voice-based phishing performed through phone calls or other voice channels.
Answer B is incorrect because Impersonation addresses a different requirement. Impersonation refers to pretending to be a trusted person, organization, or system.
Answer D is incorrect because Instant-messaging vector addresses a different security requirement. Instant-messaging vector refers to use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts.
Question 13
Which deceptive message is designed to trick a target into revealing information, opening content, or taking an unsafe action?
Correct Answer: C
Correct Answer
Answer C is correct because Phishing means a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action.
Incorrect Answers
Answer A is incorrect because Pretexting would fit a different scenario. Pretexting refers to social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request.
Answer B is incorrect because Business email compromise represents a different security function. Business email compromise refers to fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions.
Answer D is incorrect because Open service port addresses a different requirement. Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.
Question 14
To persuade a victim through spoken social engineering, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Vishing means voice-based phishing performed through phone calls or other voice channels.
Incorrect Answers
Answer A is incorrect because Open service port would fit a different scenario. Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.
Answer C is incorrect because Typosquatting addresses a different requirement. Typosquatting refers to registration or use of look-alike domain names based on common spelling mistakes.
Answer D is incorrect because Supply-chain vector addresses a different security requirement. Supply-chain vector refers to compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source.
Question 15
Which term describes phishing delivered through SMS or text messaging?
Correct Answer: D
Correct Answer
Answer D is correct because Smishing means phishing delivered through SMS or text messaging.
Incorrect Answers
Answer A is incorrect because Brand impersonation would fit a different scenario. Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users.
Answer B is incorrect because Pretexting addresses a different requirement. Pretexting refers to social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request.
Answer C is incorrect because Watering-hole attack represents a different security function. Watering-hole attack refers to compromise of a site or resource that the intended victims are known to visit.
Question 16
To create confusion even when the distributor may believe the content is true, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Misinformation means false information that is shared without necessarily intending to deceive.
Incorrect Answers
Answer A is incorrect because Voice-call vector addresses a different requirement. Voice-call vector refers to use of spoken interaction to deceive a person into revealing information or taking an unsafe action.
Answer B is incorrect because SMS-based vector would fit a different scenario. SMS-based vector refers to delivery of malicious links or deceptive requests through text messaging.
Answer C is incorrect because Watering-hole attack addresses a different security requirement. Watering-hole attack refers to compromise of a site or resource that the intended victims are known to visit.
Question 17
Which term describes false information deliberately created or spread to deceive?
Correct Answer: A
Correct Answer
Answer A is correct because Disinformation means false information deliberately created or spread to deceive.
Incorrect Answers
Answer B is incorrect because Brand impersonation addresses a different requirement. Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users.
Answer C is incorrect because Pretexting would fit a different scenario. Pretexting refers to social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request.
Answer D is incorrect because Email-based vector represents a different security function. Email-based vector refers to delivery of malicious links, attachments, requests, or social-engineering content through email.
Question 18
To obtain access or cooperation by abusing perceived identity, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Impersonation means pretending to be a trusted person, organization, or system.
Incorrect Answers
Answer B is incorrect because Default credentials addresses a different security requirement. Default credentials refers to vendor-supplied or predictable usernames and passwords that have not been changed.
Answer C is incorrect because Typosquatting addresses a different requirement. Typosquatting refers to registration or use of look-alike domain names based on common spelling mistakes.
Answer D is incorrect because SMS-based vector would fit a different scenario. SMS-based vector refers to delivery of malicious links or deceptive requests through text messaging.
Question 19
Which term describes fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions?
Correct Answer: A
Correct Answer
Answer A is correct because Business email compromise means fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions.
Incorrect Answers
Answer B is incorrect because Misinformation addresses a different requirement. Misinformation refers to false information that is shared without necessarily intending to deceive.
Answer C is incorrect because File-based vector represents a different security function. File-based vector refers to use of a malicious or weaponized file as the initial delivery mechanism.
Answer D is incorrect because Unsupported system would fit a different scenario. Unsupported system refers to a system or application that no longer receives security fixes or vendor support.
Question 20
To make a deceptive request seem legitimate through a convincing story, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Pretexting means social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request.
Incorrect Answers
Answer A is incorrect because Open service port would fit a different scenario. Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.
Answer B is incorrect because Brand impersonation addresses a different requirement. Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users.
Answer D is incorrect because Instant-messaging vector addresses a different security requirement. Instant-messaging vector refers to use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts.
Question 21
Which term describes compromise of a site or resource that the intended victims are known to visit?
Correct Answer: B
Correct Answer
Answer B is correct because Watering-hole attack means compromise of a site or resource that the intended victims are known to visit.
Incorrect Answers
Answer A is incorrect because Open service port addresses a different requirement. Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.
Answer C is incorrect because Disinformation represents a different security function. Disinformation refers to false information deliberately created or spread to deceive.
Answer D is incorrect because File-based vector would fit a different scenario. File-based vector refers to use of a malicious or weaponized file as the initial delivery mechanism.
Question 22
To make malicious content appear to originate from a legitimate brand, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Brand impersonation means use of a trusted company’s name, visual identity, or domain-like presence to deceive users.
Incorrect Answers
Answer A is incorrect because Misinformation would fit a different scenario. Misinformation refers to false information that is shared without necessarily intending to deceive.
Answer C is incorrect because Supply-chain vector addresses a different requirement. Supply-chain vector refers to compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source.
Answer D is incorrect because Email-based vector addresses a different security requirement. Email-based vector refers to delivery of malicious links, attachments, requests, or social-engineering content through email.
Question 23
Which term describes registration or use of look-alike domain names based on common spelling mistakes?
Correct Answer: D
Correct Answer
Answer D is correct because Typosquatting means registration or use of look-alike domain names based on common spelling mistakes.
Incorrect Answers
Answer A is incorrect because File-based vector would fit a different scenario. File-based vector refers to use of a malicious or weaponized file as the initial delivery mechanism.
Answer B is incorrect because Pretexting addresses a different requirement. Pretexting refers to social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request.
Answer C is incorrect because Email-based vector represents a different security function. Email-based vector refers to delivery of malicious links, attachments, requests, or social-engineering content through email.
Question 24
To reach users through a widely trusted business communication channel, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Email-based vector means delivery of malicious links, attachments, requests, or social-engineering content through email.
Incorrect Answers
Answer A is incorrect because Vulnerable software addresses a different requirement. Vulnerable software refers to software with an exploitable flaw that creates an attack surface.
Answer B is incorrect because Voice-call vector represents a different security function. Voice-call vector refers to use of spoken interaction to deceive a person into revealing information or taking an unsafe action.
Answer D is incorrect because Open service port would fit a different scenario. Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.
Question 25
Which term describes delivery of malicious links or deceptive requests through text messaging?
Correct Answer: B
Correct Answer
Answer B is correct because SMS-based vector means delivery of malicious links or deceptive requests through text messaging.
Incorrect Answers
Answer A is incorrect because Typosquatting addresses a different requirement. Typosquatting refers to registration or use of look-alike domain names based on common spelling mistakes.
Answer C is incorrect because Default credentials addresses a different security requirement. Default credentials refers to vendor-supplied or predictable usernames and passwords that have not been changed.
Answer D is incorrect because Business email compromise would fit a different scenario. Business email compromise refers to fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions.
Question 26
To exploit real-time enterprise messaging channels, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Instant-messaging vector means use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts.
Incorrect Answers
Answer B is incorrect because Removable-device vector addresses a different requirement. Removable-device vector refers to use of USB or other removable media to introduce malware or move data.
Answer C is incorrect because Watering-hole attack would fit a different scenario. Watering-hole attack refers to compromise of a site or resource that the intended victims are known to visit.
Answer D is incorrect because Smishing represents a different security function. Smishing refers to phishing delivered through SMS or text messaging.
Question 27
Which term describes use of a malicious or weaponized file as the initial delivery mechanism?
Correct Answer: B
Correct Answer
Answer B is correct because File-based vector means use of a malicious or weaponized file as the initial delivery mechanism.
Incorrect Answers
Answer A is incorrect because Typosquatting would fit a different scenario. Typosquatting refers to registration or use of look-alike domain names based on common spelling mistakes.
Answer C is incorrect because Vishing addresses a different security requirement. Vishing refers to voice-based phishing performed through phone calls or other voice channels.
Answer D is incorrect because Phishing addresses a different requirement. Phishing refers to a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action.
Question 28
To exploit trust and urgency through telephone or voice communication, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Voice-call vector means use of spoken interaction to deceive a person into revealing information or taking an unsafe action.
Incorrect Answers
Answer A is incorrect because Smishing represents a different security function. Smishing refers to phishing delivered through SMS or text messaging.
Answer B is incorrect because Disinformation would fit a different scenario. Disinformation refers to false information deliberately created or spread to deceive.
Answer D is incorrect because Unsecured wireless network addresses a different requirement. Unsecured wireless network refers to a wireless environment with weak or absent security controls.
Question 29
Which term describes use of USB or other removable media to introduce malware or move data?
Correct Answer: D
Correct Answer
Answer D is correct because Removable-device vector means use of USB or other removable media to introduce malware or move data.
Incorrect Answers
Answer A is incorrect because Unsecured wireless network addresses a different requirement. Unsecured wireless network refers to a wireless environment with weak or absent security controls.
Answer B is incorrect because Default credentials would fit a different scenario. Default credentials refers to vendor-supplied or predictable usernames and passwords that have not been changed.
Answer C is incorrect because Misinformation addresses a different security requirement. Misinformation refers to false information that is shared without necessarily intending to deceive.
Question 30
To gain access or execute code by exploiting an unpatched weakness, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Vulnerable software means software with an exploitable flaw that creates an attack surface.
Incorrect Answers
Answer A is incorrect because Brand impersonation addresses a different requirement. Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users.
Answer B is incorrect because File-based vector would fit a different scenario. File-based vector refers to use of a malicious or weaponized file as the initial delivery mechanism.
Answer C is incorrect because Vishing represents a different security function. Vishing refers to voice-based phishing performed through phone calls or other voice channels.
Question 31
Which system or application no longer receives security fixes or vendor support?
Correct Answer: C
Correct Answer
Answer C is correct because Unsupported system means a system or application that no longer receives security fixes or vendor support.
Incorrect Answers
Answer A is incorrect because Watering-hole attack addresses a different requirement. Watering-hole attack refers to compromise of a site or resource that the intended victims are known to visit.
Answer B is incorrect because Impersonation would fit a different scenario. Impersonation refers to pretending to be a trusted person, organization, or system.
Answer D is incorrect because Voice-call vector addresses a different security requirement. Voice-call vector refers to use of spoken interaction to deceive a person into revealing information or taking an unsafe action.
Question 32
To intercept traffic, gain unauthorized connectivity, or stage local attacks, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Unsecured wireless network means a wireless environment with weak or absent security controls.
Incorrect Answers
Answer A is incorrect because Typosquatting would fit a different scenario. Typosquatting refers to registration or use of look-alike domain names based on common spelling mistakes.
Answer C is incorrect because Vulnerable software addresses a different requirement. Vulnerable software refers to software with an exploitable flaw that creates an attack surface.
Answer D is incorrect because SMS-based vector represents a different security function. SMS-based vector refers to delivery of malicious links or deceptive requests through text messaging.
Question 33
Which reachable network port exposing a service may be unnecessary, misconfigured, or vulnerable?
Correct Answer: A
Correct Answer
Answer A is correct because Open service port means a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.
Incorrect Answers
Answer B is incorrect because Brand impersonation would fit a different scenario. Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users.
Answer C is incorrect because Unsecured wireless network addresses a different requirement. Unsecured wireless network refers to a wireless environment with weak or absent security controls.
Answer D is incorrect because Voice-call vector addresses a different security requirement. Voice-call vector refers to use of spoken interaction to deceive a person into revealing information or taking an unsafe action.
Question 34
To gain access by trying well-known factory credentials, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Default credentials means vendor-supplied or predictable usernames and passwords that have not been changed.
Incorrect Answers
Answer A is incorrect because File-based vector would fit a different scenario. File-based vector refers to use of a malicious or weaponized file as the initial delivery mechanism.
Answer B is incorrect because Open service port represents a different security function. Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.
Answer D is incorrect because Brand impersonation addresses a different requirement. Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users.
Question 35
Which term describes compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source?
Correct Answer: C
Correct Answer
Answer C is correct because Supply-chain vector means compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source.
Incorrect Answers
Answer A is incorrect because Business email compromise addresses a different security requirement. Business email compromise refers to fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions.
Answer B is incorrect because SMS-based vector would fit a different scenario. SMS-based vector refers to delivery of malicious links or deceptive requests through text messaging.
Answer D is incorrect because Brand impersonation addresses a different requirement. Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users.
Popular posts
Recent Posts
