Domain 2 accounts for 22 percent of the SY0-701 exam. It connects four questions that should stay together during study: Who might attack, how could they get in, what weakness would help them, and which control addresses the risk?

Attack names are useful, but scenario details usually decide the answer. A sign-in alert after impossible travel points toward a compromised credential or session. A database error after crafted input points toward injection. A vendor update that arrives through a trusted channel can still be malicious when the supply chain has been compromised.

Domain 2 map

The official objectives divide Threats, Vulnerabilities, and Mitigations into five areas:

Objective Main focus Questions to ask
2.1 Threat actors and motivations Who benefits, what resources are available, and what outcome are they seeking?
2.2 Threat vectors and attack surfaces Which path could carry the attack, and which exposed people, systems, or services are reachable?
2.3 Vulnerability types What weakness makes the attack possible?
2.4 Malicious activity and indicators What happened, and which evidence supports that conclusion?
2.5 Mitigation techniques Which control reduces the stated likelihood, exposure, or impact most directly?

Use the chain from actor to mitigation when a question feels crowded. The same malware can arrive through several vectors, exploit different vulnerabilities, and call for more than one control. Focus on the link the scenario asks you to identify.

Threat actors and motivations

A threat actor is the person, group, or organizational behavior that creates risk. The actor's location, resources, skill, and motivation help predict likely targets and methods.

Threat actor Common characteristics Likely motivations
Nation-state Well funded, patient, capable of long campaigns, and often supported by intelligence resources Espionage, strategic advantage, war, disruption, or theft of sensitive research
Unskilled attacker Relies heavily on public tools, copied instructions, or automated scanning Curiosity, attention, disruption, challenge, or opportunistic gain
Hacktivist Targets organizations connected to a social, political, or philosophical cause Publicity, protest, service disruption, data release, or reputational damage
Insider threat Has legitimate access or knowledge of internal systems, processes, and data Financial gain, revenge, coercion, espionage, convenience, or accidental harm
Organized crime Operates for profit with specialized roles, repeatable processes, and access to criminal services Ransom, fraud, theft, blackmail, credential resale, or data monetization
Shadow IT Employees or teams use unapproved services, devices, or applications outside normal oversight Speed, convenience, missing business capability, or avoidance of a slow approval process

Shadow IT is usually driven by a business need rather than hostile intent, yet it can expose data and bypass security controls. An unsanctioned file-sharing service may create the same confidentiality problem whether the employee meant harm or simply needed to send a large document.

Internal and external actors

An internal actor already has some degree of trusted access or organizational knowledge. An external actor begins outside that trust boundary. The distinction affects likely evidence and controls.

An external attacker may scan public services and steal credentials. An insider may use approved credentials from an expected location, making entitlement reviews, data-loss prevention, separation of duties, and behavior monitoring especially important.

Resources, funding, and capability

Funding influences patience, tooling, infrastructure, and the ability to replace resources after discovery. Sophistication describes capability, although a skilled actor may still choose a simple technique when it works. Password spraying and phishing remain useful because organizations continue to expose accounts and people.

Avoid selecting an actor from one clue alone. A destructive attack could support war, political protest, revenge, extortion, or an attempt to hide evidence. Combine target choice, persistence, method, and requested outcome.

Motivations

Common motivations include:

  • Data exfiltration: Removing data for resale, intelligence, fraud, publication, or later leverage.
  • Espionage: Quiet collection of government, military, commercial, or personal information.
  • Service disruption: Preventing normal operations or degrading availability.
  • Blackmail: Threatening disclosure or harm unless the victim complies.
  • Financial gain: Ransomware, payment fraud, credential theft, cryptomining, or resale of access.
  • Philosophical or political beliefs: Promoting a cause, embarrassing a target, or influencing public opinion.
  • Ethical motivation: Authorized researchers and testers may probe systems to identify weaknesses under agreed rules.
  • Revenge: Retaliation by a current or former employee, customer, contractor, or other party.
  • Disruption or chaos: Damage for its own sake or to distract defenders from another objective.
  • War: Strategic attacks against government, military, communications, logistics, or critical infrastructure.

Exam clue: Motivation can narrow the actor, but it rarely proves identity by itself. Use the full pattern of target, resources, timing, and behavior.

Threat vectors and attack surfaces

A threat vector is the path used to reach a target. The attack surface is the collection of exposed people, devices, applications, services, interfaces, and dependencies that an attacker could target.

Reducing attack surface means removing or restricting unnecessary exposure. Closing an unused port, retiring unsupported software, disabling a default account, and limiting public cloud access all remove opportunities before an attacker chooses a vector.

Vector How it reaches the target Useful clues
Message-based Email, SMS, and instant messaging carry links, requests, attachments, or false instructions Urgency, credential requests, unexpected attachments, altered sender details
Image-based Images hide links, QR codes, tracking, malicious content, or text intended to evade filtering QR-code login prompts, image-only messages, mismatched destination addresses
File-based Documents, archives, installers, scripts, and media files carry malicious code or exploit a parser Macros, unexpected file types, double extensions, unsigned installers
Voice call An attacker impersonates support, leadership, a vendor, or a trusted institution Requests to reveal codes, reset access, bypass procedure, or act immediately
Removable device USB storage or another portable device introduces files, malware, or unauthorized data movement Unknown media, newly mounted devices, execution from removable storage
Vulnerable software An exposed client, server, agent, or agentless interface contains an exploitable flaw Known vulnerable version, missing patch, reachable management interface
Supply chain A service provider, vendor, supplier, update channel, component, or dependency is compromised Trusted distribution path, valid vendor relationship, widespread downstream impact

Unsupported systems and exposed services

Unsupported systems and applications no longer receive normal security fixes. A legacy device may still perform a required function, but its risk must be addressed through isolation, restrictive access, monitoring, compensating controls, or replacement planning.

Open service ports expand the reachable attack surface. The question is whether the service is required, securely configured, patched, and limited to appropriate sources. Default credentials are especially dangerous because attackers can test them cheaply and at scale.

A client-based path depends on software installed on the endpoint, such as a vulnerable application or management agent. An agentless path reaches a browser, API, service, or remote-management interface without requiring a resident agent. The label describes how the target is reached; either approach can expose a flaw when the reachable software or interface is vulnerable.

Unsecure networks

Wireless, wired, and Bluetooth connections can expose traffic or device access when authentication, encryption, segmentation, and configuration are weak. Watch for evil-twin access points, rogue devices, unauthorized switch connections, weak wireless protocols, discoverable Bluetooth services, and untrusted public networks.

Social engineering

Social engineering targets human judgment and organizational process.

  • Phishing: A broad deceptive message, usually sent by email.
  • Spear phishing: A tailored message aimed at a specific person or group.
  • Whaling: Spear phishing aimed at executives or other high-value roles.
  • Vishing: Voice-based phishing.
  • Smishing: SMS-based phishing.
  • Impersonation: Pretending to be a trusted person, support function, vendor, or authority.
  • Business email compromise: Using a compromised or convincing business identity to redirect payments, data, or sensitive actions.
  • Pretexting: Building a believable story that gives the request a reason and context.
  • Watering-hole attack: Compromising a site commonly visited by the intended targets.
  • Brand impersonation: Copying a known organization's appearance and language.
  • Typosquatting: Registering a look-alike domain that depends on a misspelling or visual similarity.
  • Misinformation: Sharing false information without necessarily intending harm.
  • Disinformation: Deliberately creating or spreading false information to influence behavior.

Verification procedures matter because training alone cannot make every message obvious. Payment changes, password resets, unusual data requests, and requests to bypass normal controls should use an independent confirmation path.

Vulnerability types

A vulnerability is a weakness that can be exploited. A threat actor supplies intent and capability; a vector supplies the path; the vulnerability supplies the opening.

Category Examples Key distinction
Application Memory injection, buffer overflow, race condition, malicious update The weakness exists in program logic, memory handling, execution flow, or update behavior
Web-based SQL injection and cross-site scripting Untrusted input reaches a database command or browser output without safe handling
Hardware and firmware Vulnerable firmware, end-of-life equipment, legacy components The affected layer may be difficult to patch or may require replacement
Virtualization VM escape and resource reuse Isolation between guests, hosts, or previous tenants fails
Cloud-specific Public storage, excessive permissions, exposed keys, insecure service configuration Responsibility is shared, and configuration can expose resources quickly
Supply chain Compromised service, hardware, software, library, or update provider Trust in an upstream provider carries the weakness downstream
Mobile device Sideloading and jailbreaking Normal application controls or platform protections are bypassed
Misconfiguration Default passwords, public access, excessive permissions, disabled logging The product may be secureable, but the deployed settings create exposure

Operating-system and cryptographic vulnerabilities can cut across several of these categories. An outdated OS may expose a local privilege-escalation flaw. Weak algorithms, poor randomness, reused nonces, exposed keys, or incorrect certificate validation can weaken cryptographic protection.

In virtualized or shared environments, resource reuse can expose data left behind in memory, storage, snapshots, or another reassigned resource. Sanitization, secure deletion, isolation, encryption, and careful lifecycle controls reduce the chance that a later tenant or workload can recover residual data.

Memory injection and buffer overflow

Memory injection places malicious code or data into a process's memory so it can run within that process or change its behavior. Buffer overflow writes beyond an allocated memory boundary, potentially corrupting data, crashing the program, or redirecting execution.

Input validation, memory-safe development practices, compiler protections, address-space randomization, data execution prevention, patching, and application isolation can reduce exposure. The best answer depends on whether the question asks for a coding fix, a platform defense, or an immediate operational mitigation.

Race conditions and TOC/TOU

A race condition occurs when the result depends on timing or the order of operations. A time-of-check/time-of-use problem appears when a system verifies a condition, then uses the resource after that condition may have changed.

For example, an application checks that a file is safe and permitted. An attacker replaces or redirects the file before the application opens it. Atomic operations, locking, secure temporary-file handling, and designs that reduce the gap between checking and use help address the weakness.

SQL injection and cross-site scripting

SQL injection occurs when untrusted input changes the meaning of a database query. Parameterized queries, safe APIs, input handling, least-privileged database accounts, and defensive monitoring reduce risk.

Cross-site scripting (XSS) allows untrusted content to execute in another user's browser under the affected site's context. Context-aware output encoding, safe templating, input handling, content security policy, and secure cookie settings help limit exposure and impact.

The location of execution separates the two. SQL injection targets the application's database interaction. XSS targets browser-rendered content and the user's session.

Malicious updates and supply-chain flaws

A malicious update may be inserted by compromising a vendor, build system, signing process, distribution service, administrator account, or dependency. The file can arrive through an expected channel and still be harmful.

Code signing, reproducible builds, protected build pipelines, dependency review, staged rollout, behavior monitoring, and the ability to revoke trust all help. A valid signature confirms that a signing key approved the file. Defenders must also protect that key and the process using it.

Zero-day vulnerabilities

A zero-day vulnerability is unknown to the responsible vendor or lacks an available fix when attackers can exploit it. Defenders rely on layered controls such as isolation, least privilege, behavior monitoring, exploit protection, application control, segmentation, and temporary configuration changes until a patch or replacement becomes available.

Malicious activity and indicators

Objective 2.4 asks you to analyze indicators. Begin with the evidence, then choose the attack that explains it with the fewest unsupported assumptions.

Malware behavior

Malware Behavior Common clue
Ransomware Encrypts or disrupts systems and demands payment; may also steal data Inaccessible files, ransom note, unusual encryption activity
Trojan Appears legitimate or useful while delivering hidden malicious behavior User-installed program followed by unexpected access or payload execution
Worm Self-propagates across systems or networks Rapid spread without each user launching a copy
Spyware Collects activity, communications, credentials, or other information Unexpected monitoring, outbound connections, or privacy loss
Bloatware Adds unnecessary software that consumes resources or expands attack surface Preinstalled or bundled applications with little business value
Virus Attaches to a host file or program and spreads when that host runs Modified files and execution-dependent propagation
Keylogger Records keystrokes to capture credentials or sensitive information Stolen input despite otherwise normal application behavior
Logic bomb Triggers when a defined condition or time occurs Delayed action tied to a date, account state, or event
Rootkit Hides malicious activity and maintains privileged persistence System-level manipulation, hidden processes, altered security tools

Malware labels can overlap. A Trojan may install spyware or a rootkit. Ransomware may arrive through phishing and then spread like a worm. Select the term tied to the behavior emphasized in the question.

Physical, network, application, and cryptographic attacks

  • Physical brute force: Forcing a door, lock, enclosure, or other physical barrier. Context separates this from password brute force.
  • RFID cloning: Copying identifier data from a badge or tag to impersonate the original device.
  • Environmental attack: Using heat, water, smoke, power loss, or another environmental condition to damage or interrupt systems.
  • Distributed denial-of-service: Many sources overwhelm a target. Reflected attacks send replies toward the victim using a spoofed source; amplified attacks produce responses larger than the original requests.
  • DNS attack: Manipulating, poisoning, redirecting, tunneling through, or exhausting DNS services.
  • Wireless attack: Rogue access points, evil twins, deauthentication, weak encryption, or unauthorized association.
  • On-path attack: Intercepting and possibly altering communications between parties.
  • Credential replay: Reusing captured authentication material or a valid session artifact.
  • Injection: Supplying input that becomes part of a command, query, or interpreted instruction.
  • Replay: Resending a previously valid transmission to repeat an action or authentication.
  • Privilege escalation: Gaining permissions beyond those originally assigned.
  • Forgery: Creating a false token, request, message, signature, or identity representation.
  • Directory traversal: Using path manipulation to reach files outside the intended directory.
  • Downgrade attack: Forcing weaker protocol, algorithm, or security settings.
  • Collision attack: Finding different inputs that produce the same hash output.
  • Birthday attack: Exploiting collision probability to find a matching hash more efficiently than testing one exact preimage.

Password spraying and brute force

A brute-force password attack tries many candidate passwords against a target account or protected value. Password spraying tries a small number of common passwords across many accounts, often to avoid repeated failures on one account.

The logs may reveal the difference. Many failures against one user suggest focused guessing. One or two failures across a wide account list suggest spraying. Distributed sources can blur the picture, so consider timing, account patterns, lockouts, and successful follow-on access.

Indicators to recognize

Indicator What it may suggest What to verify
Account lockout Repeated failed authentication, password guessing, or a stale automated credential Targeted accounts, source addresses, timing, and recent password changes
Concurrent sessions Credential sharing, stolen credentials, or a legitimate multi-device session Locations, device identity, session tokens, and normal user behavior
Impossible travel Sign-ins from locations that cannot reasonably be reached in the elapsed time VPN use, proxy services, device history, and authentication strength
Resource consumption Denial-of-service, cryptomining, runaway process, malware, or legitimate demand Process owner, traffic pattern, time of onset, and affected systems
Missing or out-of-cycle logs Log tampering, disabled collection, system failure, or an unplanned process Collector health, time synchronization, retention, permissions, and alternate sources
Blocked content A control intercepted malicious, prohibited, or misclassified traffic Rule matched, source, destination, payload, and false-positive history
Resource inaccessibility Ransomware, outage, denial-of-service, permission change, or storage failure Error details, system health, recent changes, and access from other locations

Published or documented indicators can include known malicious domains, file hashes, IP addresses, certificates, tactics, or patterns. They help detection, but context and freshness matter. Attackers can replace infrastructure quickly, and benign systems can sometimes reuse an address or service previously associated with abuse.

Mitigation techniques

A mitigation reduces likelihood, exposure, or impact. Choose the control that addresses the weakness described in the scenario rather than the control with the broadest reputation.

Mitigation Primary purpose Example
Segmentation Limits reachability and lateral movement between systems or trust zones Separating user devices, servers, management systems, and industrial equipment
Access control Restricts actions through identities, permissions, ACLs, and policy Allowing a service account to read one queue while denying administrative changes
Application allow list Permits approved executables, scripts, or code and blocks unapproved items Allowing signed business applications on a kiosk
Isolation Separates a risky or compromised system from normal communication Quarantining an endpoint after ransomware behavior is detected
Patching Corrects known software or firmware flaws Prioritizing an internet-facing vulnerability with active exploitation
Encryption Protects confidentiality of data at rest or in transit Encrypting a lost laptop's storage and administrative network sessions
Monitoring Detects suspicious activity and supplies evidence for response Alerting on impossible travel, new persistence, or unusual data transfer
Least privilege Limits each identity or process to the permissions required for its task Removing local administrator rights from ordinary user accounts
Configuration enforcement Maintains approved settings and corrects drift Reapplying a secure baseline when a firewall or logging setting changes
Decommissioning Removes unsupported or unnecessary assets and their exposure Retiring an obsolete server after migrating its required function

Hardening techniques

Hardening reduces unnecessary capability and applies secure defaults. Common actions include:

  • Enabling appropriate encryption
  • Installing endpoint protection
  • Enabling a host-based firewall
  • Deploying a host-based intrusion prevention system
  • Disabling unused ports and protocols
  • Changing default passwords
  • Removing unnecessary software

Hardening should follow an approved baseline and include testing. Disabling a service blindly can create an outage; leaving every service enabled creates unnecessary exposure. The secure choice supports the required function with the smallest reasonable attack surface.

Choosing among similar mitigations

  • Use patching when a supported fix corrects the vulnerable code.
  • Use configuration enforcement when the product is secureable but settings have drifted or were deployed incorrectly.
  • Use isolation when communication must stop quickly or a system cannot yet be remediated.
  • Use segmentation to limit routine reachability and contain future movement between zones.
  • Use application allow listing when only approved code should run.
  • Use least privilege to reduce what a compromised account or process can do.
  • Use decommissioning when the asset no longer justifies its risk or cannot be supported safely.

Patching is a process rather than a single click. Identify the affected assets, prioritize risk, acquire and test the update, deploy it, verify installation, and monitor for problems. Active exploitation, public exposure, business importance, and available compensating controls all affect priority.

Exam clue: The strongest answer usually addresses the stated vulnerability or attack path directly. A generic security improvement may be helpful and still lose to the control that closes the actual opening.

Common Domain 2 exam traps

Choosing the actor from the attack name

Ransomware suggests financial gain, yet the same technique could support disruption, espionage, or destruction. Use target selection, requested outcome, resources, and campaign behavior.

Confusing vector, vulnerability, and payload

A phishing email is a vector. A vulnerable macro or browser may provide the weakness. The installed remote-access Trojan is the payload. Questions often include all three and ask for only one.

Calling every deceptive message phishing

Email points toward phishing. SMS points toward smishing. A voice call points toward vishing. Pretexting describes the invented story, and impersonation describes the assumed identity. More than one label may apply, so match the wording of the question.

Mixing password spraying with brute force

Spraying distributes a few likely passwords across many accounts. Focused brute force tries many candidates against one account or protected value. Account and timing patterns provide the clue.

Assuming a valid update channel guarantees safe code

Supply-chain compromise can abuse a trusted vendor, build process, signing key, or distribution service. Verify integrity, provenance, behavior, and the security of the process behind the signature.

Picking encryption for an integrity or availability problem

Encryption protects confidentiality. It may support other goals as part of a larger protocol, but it does not restore an unavailable service or prove that every file is unmodified.

Using monitoring as the only mitigation

Monitoring helps detect and investigate. When the question asks how to prevent execution, close a port, remove excessive access, or correct vulnerable code, choose the control that changes the exposure.

Domain 2 review checklist

Before moving on, check whether you can do the following without relying on answer choices:

  • Compare nation-state, unskilled, hacktivist, insider, organized-crime, and shadow-IT threats.
  • Use actor location, funding, capability, target, and motivation together.
  • Separate a threat vector from an attack surface, vulnerability, payload, and indicator.
  • Recognize phishing, vishing, smishing, business email compromise, pretexting, watering holes, brand impersonation, and typosquatting.
  • Explain how unsupported systems, open ports, default credentials, unsecure networks, and supply-chain dependencies expand exposure.
  • Compare memory injection, buffer overflow, race conditions, SQL injection, XSS, VM escape, misconfiguration, sideloading, jailbreaking, and zero-day flaws.
  • Distinguish ransomware, Trojans, worms, spyware, viruses, keyloggers, logic bombs, and rootkits by behavior.
  • Recognize DDoS reflection and amplification, on-path attacks, credential replay, directory traversal, privilege escalation, and cryptographic downgrade or collision attacks.
  • Separate password spraying from focused brute force.
  • Interpret account lockouts, concurrent sessions, impossible travel, resource consumption, inaccessible resources, and missing logs in context.
  • Match segmentation, access control, allow listing, isolation, patching, encryption, monitoring, least privilege, configuration enforcement, decommissioning, and hardening to their purposes.
  • Explain why the selected mitigation addresses the stated weakness more directly than the alternatives.

Apply the chain from actor to mitigation. Start a randomized SY0-701 practice test, then review which clue identified the attack path or the most direct control.

Official references

This guide follows the Threats, Vulnerabilities, and Mitigations topics listed in the official SY0-701 objectives. Use the current objectives as the final exam checklist.

Security+ SY0-701 Study Guide Return to the full exam roadmap, domain priorities, and study plan. Domain 1: General Security Concepts Review controls, zero trust, change management, cryptography, and PKI. Domain 3: Security Architecture Continue with infrastructure design, data protection, resilience, and recovery planning. Take a randomized SY0-701 practice test Apply these concepts in 10, 20, 30, or 50-question sessions.