Study. uk . com
  1. Home
  2. All questions
  3. Threats

CompTIA Security+ study material: Threats

61 questions of the 611 in the CompTIA Security+ quiz. Each opens with its answer, the reasoning and where that is written down.

Challenge yourself on this topic → Study as cards

The questions

  1. 3. A power supply fails and takes a database offline. Under the standard definition, how should this be classified?
  2. 4. Which two of the following are recognised categories of threat source? Choose two.
  3. 6. After an organisation deploys strong controls on its public web tier, attackers begin targeting a smaller partner instead. What is this behaviour called?
  4. 11. A threat report describes how a group gains access, moves laterally and exfiltrates data, without naming any specific tool. What is being described?
  5. 68. Which two backup properties most directly determine whether an organisation can recover from ransomware without paying? Choose two.
  6. 70. An organisation restores cleanly from backup after a ransomware attack, yet still faces a serious problem. What is it?
  7. 92. During a test, an assessor gathers information about the target using only public records and search engines. What is the main advantage of this approach?
  8. 99. Why do perimeter controls contribute little against an insider threat?
  9. 100. A department signs up for an unapproved file-sharing service. What is the primary security concern?
  10. 170. Why do supply chain vulnerabilities defeat controls aimed at untrusted input?
  11. 205. A fake set of credentials is planted in a document share. It is later used to attempt a login. What has this proved?
  12. 226. A signed vendor update is later found to contain malicious code. What does this show about signature verification?
  13. 268. Before sending an authentication code over the telephone network, which two risk indicators should a verifier consider? Choose two.
  14. 370. Why does MITRE list privileged account management as a mitigation in its own right?
  15. 389. How does DNS filtering interrupt an intrusion before any connection is made?
  16. 406. An organisation relies on synchronous replication to a second site as its ransomware defence. What is the flaw?
  17. 419. In MITRE ATT&CK, what is the difference between a tactic and a technique?
  18. 420. An adversary registers domains and builds infrastructure before any contact with the target. Which ATT&CK tactic is this?
  19. 421. Which ATT&CK tactic most directly enables an attacker to move from one compromised host to the rest of the estate?
  20. 422. An adversary encrypts a victim's file servers to disrupt operations. Which ATT&CK tactic does this fall under?
  21. 423. Why does analysing outbound traffic often reveal an intrusion the perimeter missed?
  22. 424. Why does MITRE catalogue Valid Accounts as a technique in its own right?
  23. 425. An organisation focuses its defences entirely on user awareness training. Which initial-access technique does this leave unaddressed?
  24. 426. What do ATT&CK data sources tell a detection team?
  25. 427. A team publishes an ATT&CK coverage map with no version recorded. Why is this a problem?
  26. 428. What most distinguishes a nation-state actor from other threat actors?
  27. 429. Why do campaigns by unskilled attackers tend to appear soon after a vulnerability is disclosed?
  28. 430. Which outcome is most characteristic of hacktivist activity?
  29. 431. Why does the ATT&CK Initial Access tactic have limited relevance to an insider threat?
  30. 432. Which two are recognised threat vectors on the exam? Choose two.
  31. 433. An organisation filters email thoroughly but has no controls on SMS or instant messaging. Why does the vector distinction matter?
  32. 434. Why does generic awareness messaging fail against spear phishing?
  33. 435. A finance clerk receives a convincing instruction to change a supplier's bank details and complies. No malware was involved. What is this attack called?
  34. 436. An attacker compromises an industry news site frequently read by employees of one company. Which technique is this?
  35. 437. An attacker registers a domain differing from a bank's by one transposed letter. What is this technique, and what does it exploit?
  36. 438. An attacker calls the help desk posing as a travelling executive locked out before a board meeting. Which social engineering element is central?
  37. 439. Which two psychological levers do social engineers most commonly use, and why? Choose two.
  38. 440. According to CISA, which two are common ransomware initial access routes? Choose two.
  39. 441. Which control does CISA recommend for remote desktop services that must remain available?
  40. 442. On discovering ransomware, an administrator wants to wipe and rebuild the affected servers immediately. What should happen first?
  41. 443. A board asks for threat intelligence to inform next year's security budget. Which tier is appropriate?
  42. 444. An assessor builds a target profile from company registrations, job adverts and public code repositories. What is this activity?
  43. 445. How does an indicator of attack differ from an indicator of compromise?
  44. 446. Why does behaviour-based detection built on ATT&CK techniques outlast an indicator feed?
  45. 447. A retailer subscribes to a threat feed aimed at industrial control operators. What is the likely result?
  46. 448. What distinguishes threat hunting from alert triage?
  47. 449. Which measure best characterises an advanced persistent threat?
  48. 450. Why is an untrusted wireless network a threat vector even when both endpoints are patched?
  49. 451. How does malware most commonly reach an air-gapped network?
  50. 452. Why is a malicious update through a legitimate vendor channel especially hard to stop?
  51. 453. Beyond a remediation list, what does the Known Exploited Vulnerabilities catalog tell a defender?
  52. 454. An analyst joins a sector information sharing community. Which notation tells them how widely each item may be redistributed?
  53. 455. Why does attachment sandboxing sit alongside link filtering rather than replacing it?
  54. 589. An adversary sends a malicious attachment that establishes a foothold on a workstation. Which ATT&CK tactic has been achieved?
  55. 590. An attacker enumerates domain accounts, shares and running services on a compromised host. Which tactic is this?
  56. 591. A team looks for a one-to-one mapping between ATT&CK mitigations and products to buy. Why does this not work?
  57. 592. Which two motivations does the exam name for threat actors? Choose two.
  58. 593. Why do ransomware operations run affiliate programmes, negotiation teams and leak sites?
  59. 594. Why are voice phishing and SMS phishing treated as separate vectors from email phishing?
  60. 595. How does reducing the attack surface differ from hardening what remains?
  61. 609. An organisation's backup server is domain-joined and reachable with production administrator credentials. Why does this defeat the backup's purpose?