- Home
- All questions
- Threats
CompTIA Security+ study material: Threats
61 questions of the 611 in the CompTIA Security+ quiz. Each opens with its answer, the reasoning and where that is written down.
Challenge yourself on this topic → Study as cards
The questions
- 3. A power supply fails and takes a database offline. Under the standard definition, how should this be classified?
- 4. Which two of the following are recognised categories of threat source? Choose two.
- 6. After an organisation deploys strong controls on its public web tier, attackers begin targeting a smaller partner instead. What is this behaviour called?
- 11. A threat report describes how a group gains access, moves laterally and exfiltrates data, without naming any specific tool. What is being described?
- 68. Which two backup properties most directly determine whether an organisation can recover from ransomware without paying? Choose two.
- 70. An organisation restores cleanly from backup after a ransomware attack, yet still faces a serious problem. What is it?
- 92. During a test, an assessor gathers information about the target using only public records and search engines. What is the main advantage of this approach?
- 99. Why do perimeter controls contribute little against an insider threat?
- 100. A department signs up for an unapproved file-sharing service. What is the primary security concern?
- 170. Why do supply chain vulnerabilities defeat controls aimed at untrusted input?
- 205. A fake set of credentials is planted in a document share. It is later used to attempt a login. What has this proved?
- 226. A signed vendor update is later found to contain malicious code. What does this show about signature verification?
- 268. Before sending an authentication code over the telephone network, which two risk indicators should a verifier consider? Choose two.
- 370. Why does MITRE list privileged account management as a mitigation in its own right?
- 389. How does DNS filtering interrupt an intrusion before any connection is made?
- 406. An organisation relies on synchronous replication to a second site as its ransomware defence. What is the flaw?
- 419. In MITRE ATT&CK, what is the difference between a tactic and a technique?
- 420. An adversary registers domains and builds infrastructure before any contact with the target. Which ATT&CK tactic is this?
- 421. Which ATT&CK tactic most directly enables an attacker to move from one compromised host to the rest of the estate?
- 422. An adversary encrypts a victim's file servers to disrupt operations. Which ATT&CK tactic does this fall under?
- 423. Why does analysing outbound traffic often reveal an intrusion the perimeter missed?
- 424. Why does MITRE catalogue Valid Accounts as a technique in its own right?
- 425. An organisation focuses its defences entirely on user awareness training. Which initial-access technique does this leave unaddressed?
- 426. What do ATT&CK data sources tell a detection team?
- 427. A team publishes an ATT&CK coverage map with no version recorded. Why is this a problem?
- 428. What most distinguishes a nation-state actor from other threat actors?
- 429. Why do campaigns by unskilled attackers tend to appear soon after a vulnerability is disclosed?
- 430. Which outcome is most characteristic of hacktivist activity?
- 431. Why does the ATT&CK Initial Access tactic have limited relevance to an insider threat?
- 432. Which two are recognised threat vectors on the exam? Choose two.
- 433. An organisation filters email thoroughly but has no controls on SMS or instant messaging. Why does the vector distinction matter?
- 434. Why does generic awareness messaging fail against spear phishing?
- 435. A finance clerk receives a convincing instruction to change a supplier's bank details and complies. No malware was involved. What is this attack called?
- 436. An attacker compromises an industry news site frequently read by employees of one company. Which technique is this?
- 437. An attacker registers a domain differing from a bank's by one transposed letter. What is this technique, and what does it exploit?
- 438. An attacker calls the help desk posing as a travelling executive locked out before a board meeting. Which social engineering element is central?
- 439. Which two psychological levers do social engineers most commonly use, and why? Choose two.
- 440. According to CISA, which two are common ransomware initial access routes? Choose two.
- 441. Which control does CISA recommend for remote desktop services that must remain available?
- 442. On discovering ransomware, an administrator wants to wipe and rebuild the affected servers immediately. What should happen first?
- 443. A board asks for threat intelligence to inform next year's security budget. Which tier is appropriate?
- 444. An assessor builds a target profile from company registrations, job adverts and public code repositories. What is this activity?
- 445. How does an indicator of attack differ from an indicator of compromise?
- 446. Why does behaviour-based detection built on ATT&CK techniques outlast an indicator feed?
- 447. A retailer subscribes to a threat feed aimed at industrial control operators. What is the likely result?
- 448. What distinguishes threat hunting from alert triage?
- 449. Which measure best characterises an advanced persistent threat?
- 450. Why is an untrusted wireless network a threat vector even when both endpoints are patched?
- 451. How does malware most commonly reach an air-gapped network?
- 452. Why is a malicious update through a legitimate vendor channel especially hard to stop?
- 453. Beyond a remediation list, what does the Known Exploited Vulnerabilities catalog tell a defender?
- 454. An analyst joins a sector information sharing community. Which notation tells them how widely each item may be redistributed?
- 455. Why does attachment sandboxing sit alongside link filtering rather than replacing it?
- 589. An adversary sends a malicious attachment that establishes a foothold on a workstation. Which ATT&CK tactic has been achieved?
- 590. An attacker enumerates domain accounts, shares and running services on a compromised host. Which tactic is this?
- 591. A team looks for a one-to-one mapping between ATT&CK mitigations and products to buy. Why does this not work?
- 592. Which two motivations does the exam name for threat actors? Choose two.
- 593. Why do ransomware operations run affiliate programmes, negotiation teams and leak sites?
- 594. Why are voice phishing and SMS phishing treated as separate vectors from email phishing?
- 595. How does reducing the attack surface differ from hardening what remains?
- 609. An organisation's backup server is domain-joined and reachable with production administrator credentials. Why does this defeat the backup's purpose?