🏠 Home 📚 Resources Threats & Vulnerabilities
⚠️ Security+ SY0-701 - Exam Objective 2

Threats and Vulnerabilities

Master threat actors, attack vectors, vulnerabilities, social engineering, and third-party risks for the CompTIA Security+ SY0-701 exam

📅 Updated January 2025 📖 10 min read ✍️ By Security+ Team

This section covers Exam Objective 2 of the CompTIA Security+ SY0-701 exam. It explains the types of threat actors, attack vectors, vulnerabilities, and risks that cybersecurity professionals must understand and mitigate.

👥 Threat Actors & Motivations

Understanding who is attacking you is crucial. From Script Kiddies to Advanced Persistent Threats (APTs), each actor has different motivations and capabilities.

Deep Dive: Threat Actors

🎯 Attack Surfaces & Vectors

The attack surface includes all points an attacker could exploit. Attack vectors are specific paths used to breach systems, such as:

⚠️ Vulnerabilities & Exploits

A vulnerability is a weakness; an exploit is the way to use it. Learn about Zero-Day attacks, Supply Chain compromises, and common software flaws.

Deep Dive: Vulnerabilities

🎣 Lure-Based & Message-Based Vectors

🔗 Third-Party Risks

When relying on vendors or cloud providers, risks include:

🧠 Social Engineering

Hacking the human is often easier than hacking the network. Explore Phishing, Vishing, Tailgating, and the psychological principles of influence.

Deep Dive: Social Engineering

📚 Additional Resources

🎯 Ready to Test Your Knowledge?

Take our free Security+ Practice Quiz and see how well you understand threats and vulnerabilities!

Start Practice Quiz →