44 Threats, Attacks & Vulnerabilities Practice Questions & Answers
Every Threats, Attacks & Vulnerabilities practice question from the CompTIA Security+ Practice Test, with the correct answer and a short explanation.
Start practice test →1. For 14 months an aerospace firm hosted an intruder who used custom malware, moved slowly, and copied engineering design files. Nothing was ransomed, sold, or published. Which threat actor is MOST likely?
- A.An organized crime group
- B.A hacktivist collective
- C.An unskilled attacker
- D.A nation-state actor✓ Answer
Custom tooling, extensive resources, a very long dwell time, and quiet theft of intellectual property with no attempt to monetize it point to espionage by a nation-state actor operating as an advanced persistent threat. Organized crime monetizes stolen data quickly, hacktivists seek publicity, and an unskilled attacker lacks the funding and sophistication for a multi-year covert operation.
Source: CompTIA Security+ SY0-701 Obj. 2.1 — threat actor attributes (resources/funding, sophistication) and motivation (espionage)Report a problem with this question
2. A criminal enterprise operates ransomware as a business: it employs developers, negotiators, and money launderers, and it splits proceeds with affiliates. Which threat actor category BEST describes it?
- A.Insider threat
- B.Organized crime✓ Answer
- C.Nation-state actor
- D.Hacktivist
Organized crime is defined by a structured, funded group with specialized roles whose motivation is consistently financial gain, which is exactly what a profit-sharing ransomware operation is. Hacktivists act on ideology, nation-states pursue strategic intelligence, and an insider threat operates from inside the victim organization using its own access.
Source: CompTIA Security+ SY0-701 Obj. 2.1 — organized crime; motivation: financial gainReport a problem with this question
3. An investigation shows the attacker downloaded a prebuilt denial-of-service tool from a public forum, ran it with default settings, and could not explain how it worked. Which threat actor attribute set fits BEST?
- A.External, limited resources, low sophistication✓ Answer
- B.External, extensive resources, high sophistication
- C.Internal, departmental budget, convenience-driven
- D.Internal, existing access, moderate sophistication
Using someone else's prebuilt tool without understanding it is the defining marker of the unskilled attacker: external to the organization, minimal resources, and low capability. High sophistication implies custom development, while the two internal profiles describe insider threat and shadow IT.
Source: CompTIA Security+ SY0-701 Obj. 2.1 — unskilled attacker (internal/external, resources, sophistication)Report a problem with this question
4. During a public policy debate, a group defaces a government agency's website with a protest banner, floods it with traffic, and posts a manifesto claiming credit. Which threat actor is MOST likely?
- A.Unskilled attacker
- B.Hacktivist✓ Answer
- C.Organized crime
- D.Shadow IT
Defacement plus service disruption plus a public claim of responsibility signals a philosophical or political motivation and a desire for visibility, which is the hacktivist profile. Criminal groups avoid publicity because it interferes with profit, and shadow IT is not an attacking actor at all.
Source: CompTIA Security+ SY0-701 Obj. 2.1 — hacktivist; motivations: philosophical/political beliefs, service disruptionReport a problem with this question
5. A marketing team, frustrated by slow IT ticket turnaround, buys a cloud file-sharing subscription on a department card and moves customer files into it. Security learns of it months later. Which BEST describes this?
- A.Insider threat
- B.Supply chain attack
- C.Organized crime
- D.Shadow IT✓ Answer
Shadow IT is an internal actor that adopts unapproved technology for convenience rather than malice, which is why intent is the tiebreaker against insider threat. The risk is real because the data leaves governed systems, but no one in the scenario is trying to harm the organization.
Source: CompTIA Security+ SY0-701 Obj. 2.1 — shadow IT (internal, motivation: convenience/bypassing IT)Report a problem with this question
6. A database administrator who was passed over for promotion copies salary records to personal storage and later alters payroll entries. Which mitigation combination would have BEST limited this?
- A.Least privilege with separation of duties and recurring access reviews✓ Answer
- B.A guest wireless network with client isolation
- C.Antivirus signature updates on all endpoints
- D.Perimeter firewall rules and DNS filtering
An insider threat is hard to detect precisely because the activity uses legitimate, already-granted access, so perimeter and malware controls do not apply. Least privilege shrinks what the account can reach, separation of duties prevents one person from both changing and approving payroll, and recurring access reviews remove entitlements that are no longer justified.
Source: CompTIA Security+ SY0-701 Obj. 2.1 (insider threat) and Obj. 2.5 (least privilege, access control)Report a problem with this question
7. An employee finds an unlabeled USB drive in the company parking lot and plugs it into a workstation, which then executes a hidden payload. Which threat vector does this BEST illustrate?
- A.Open service ports
- B.Supply chain
- C.Removable device✓ Answer
- D.Watering hole
A removable device vector delivers code by physically attaching media that the host trusts and processes, bypassing network-based inspection entirely. The standard mitigations are configuration enforcement that disables or restricts removable media, endpoint protection, and user training on found devices and cables.
Source: CompTIA Security+ SY0-701 Obj. 2.2 — threat vectors: removable deviceReport a problem with this question
8. Dozens of unrelated companies are breached the same week. Each used the same managed service provider, and the malware arrived inside a signed update from the provider's remote management tool. Which vector is this?
- A.Supply chain✓ Answer
- B.Default credentials
- C.Unsecure networks
- D.Watering hole
A supply chain attack compromises a trusted vendor, supplier, or managed service provider so that malicious code inherits the trust customers already extend to that provider's software or access. A watering hole differs because victims are infected by visiting a compromised website, not by installing something the vendor pushed to them.
Source: CompTIA Security+ SY0-701 Obj. 2.2 — supply chain (MSPs, vendors, suppliers)Report a problem with this question
9. An employee receives a phone call from a spoofed number. The caller says he is from the corporate help desk, says an account lockout must be cleared before a deadline, and asks for the employee's one-time MFA code. Which technique is this?
- A.Typosquatting
- B.Watering hole
- C.Vishing✓ Answer
- D.Smishing
Vishing is social engineering delivered over a voice call or VoIP, and caller ID spoofing plus manufactured urgency is its classic form. Smishing would arrive as an SMS text message, while watering hole and typosquatting are web-based vectors that never involve contacting the victim directly by voice.
Source: CompTIA Security+ SY0-701 Obj. 2.2 — human vectors: vishing (voice call)Report a problem with this question
10. Accounts payable receives an email from the CFO's real mailbox instructing an urgent change to a supplier's bank details before quarter close. The CFO later says he never sent it. Which attack is this MOST likely?
- A.Smishing
- B.Brand impersonation
- C.Business email compromise✓ Answer
- D.Misinformation
Business email compromise uses a compromised or convincingly spoofed executive or business mailbox to drive a fraudulent payment or a change of banking and invoice details, and the authority of the sender plus deadline pressure is what makes it work. The mitigation is an out-of-band callback to a known-good number before any payment detail is changed.
Source: CompTIA Security+ SY0-701 Obj. 2.2 — human vectors: business email compromiseReport a problem with this question
11. An attacker builds a detailed cover story about being an external auditor performing a compliance review, complete with fabricated engagement numbers and a supposed sponsor in Finance, to talk his way into a data center. What is the fabricated scenario itself called?
- A.Watering hole
- B.Disinformation
- C.Pretexting✓ Answer
- D.Brand impersonation
Pretexting is the invented backstory that makes an illegitimate request feel plausible and routine; impersonation is the narrower act of claiming to be a specific person or role, and here it is the elaborate scenario, not just the claimed identity, that carries the attack. Brand impersonation targets a company's visual identity, so it does not fit an in-person access attempt.
Source: CompTIA Security+ SY0-701 Obj. 2.2 — human vectors: pretexting vs. impersonationReport a problem with this question
12. Several engineers at one firm are infected the same morning. None received a suspicious email; all had visited an industry standards association site they read weekly, which was serving a malicious script. Which technique is this?
- A.Watering hole✓ Answer
- B.Smishing
- C.Typosquatting
- D.Business email compromise
A watering hole attack compromises a legitimate third-party site that a target population visits habitually, so victims are infected without the attacker ever contacting them directly. The absence of any lure message is the strongest clue, since phishing, smishing, and BEC all require a delivered message.
Source: CompTIA Security+ SY0-701 Obj. 2.2 — human vectors: watering holeReport a problem with this question
13. Users who mistype the company's domain by one character reach a site that copies the real login page. Registering that near-miss domain is BEST described as which technique?
- A.Watering hole
- B.Typosquatting✓ Answer
- C.Brand impersonation
- D.Pretexting
Typosquatting, also called URL hijacking, exploits predictable keyboard errors by registering domain strings that differ slightly from the real one. The tiebreaker against brand impersonation is what is being faked: typosquatting fakes the domain string, while brand impersonation fakes the logo, colors, and look and feel.
Source: CompTIA Security+ SY0-701 Obj. 2.2 — human vectors: typosquatting (URL hijacking) vs. brand impersonationReport a problem with this question
14. A coordinated network of fake accounts deliberately publishes fabricated safety claims about a manufacturer's product to damage it. Which term BEST describes this activity?
- A.Impersonation
- B.Misinformation
- C.Disinformation✓ Answer
- D.Pretexting
Intent is the discriminator: disinformation is false content spread deliberately to deceive or influence, while misinformation is false content shared by people who believe it is true. The coordinated fake-account network and the stated goal of damaging the target establish deliberate deception.
Source: CompTIA Security+ SY0-701 Obj. 2.2 — human vectors: misinformation/disinformationReport a problem with this question
15. A user believes an email is a phishing attempt. According to security awareness best practice, what should the user do FIRST?
- A.Forward it to coworkers so they are warned
- B.Reply to the sender asking them to verify who they are
- C.Delete it immediately to remove the risk
- D.Report it through the organization's defined reporting process without forwarding or deleting it✓ Answer
Awareness programs depend on a single defined reporting path so the security team can analyze headers and payloads and hunt for other recipients; deleting destroys that evidence and forwarding spreads the malicious content. Replying also confirms to the attacker that the mailbox is live and monitored.
Source: CompTIA Security+ SY0-701 Obj. 5.6 — security awareness: phishing reporting and monitoringReport a problem with this question
16. Overnight, malware spreads from one server to hundreds of hosts across the internal network. No user opened an attachment or ran a program. Which malware type is this?
- A.Worm✓ Answer
- B.Trojan
- C.Logic bomb
- D.Virus
A worm is self-propagating: it spreads across a network on its own by exploiting services or credentials, with no user interaction required. A virus is the opposite side of that distinction because it attaches to a host file or program and needs a user to execute it, and a trojan requires the user to install it willingly.
Source: CompTIA Security+ SY0-701 Obj. 2.4 — malware attacks: worm vs. virusReport a problem with this question
17. A user installs a free PDF converter from a third-party download site. It converts files as advertised, but it also opens a persistent outbound channel that lets an attacker browse the user's files remotely. Which malware type BEST fits?
- A.Remote access trojan (RAT)✓ Answer
- B.Bloatware
- C.Worm
- D.Ransomware
A trojan is malware disguised as legitimate or desirable software that the user installs willingly, and the added remote-control channel makes it specifically a remote access trojan. The persistent outbound connection back to the attacker, often on regular intervals, is the beaconing behavior that separates remote-control malware from a self-spreading worm.
Source: CompTIA Security+ SY0-701 Obj. 2.4 — malware attacks: trojan; RAT in the acronym listReport a problem with this question
18. A host makes small, regularly timed outbound connections to the same external address around the clock. The installed antivirus reports the system clean, and some expected security logs are missing. Which action is MOST likely to detect the underlying compromise?
- A.Clear the browser cache and reset the user's password
- B.Add an outbound firewall rule and consider the issue resolved
- C.Boot the host from trusted external media and perform an offline scan and integrity check✓ Answer
- D.Run another full scan with the installed antivirus
Regular beaconing plus missing logs plus a clean antivirus result points to a rootkit, which hides at or below the operating system and therefore subverts the very tools that would report it. Detection must come from outside the running OS through offline or boot-time scanning, file integrity monitoring, Secure Boot, or reimaging.
Source: CompTIA Security+ SY0-701 Obj. 2.4 — malware attacks: rootkit; indicators: missing logsReport a problem with this question
19. Three weeks after a systems administrator resigns, a scheduled script begins deleting database backups. Analysis shows the code was planted months earlier and was set to run only if that administrator's account no longer appeared in the directory. Which malware type is this?
- A.Ransomware
- B.Worm
- C.Logic bomb✓ Answer
- D.Spyware
A logic bomb is dormant code that executes only when a defined condition is met, such as a date, a file change, or the removal of an account, which makes it the classic insider-threat payload. Ransomware would encrypt data and demand payment rather than silently destroy backups, and nothing here spreads on its own.
Source: CompTIA Security+ SY0-701 Obj. 2.4 — malware attacks: logic bombReport a problem with this question
20. Credentials keep being stolen from a shared lobby kiosk. Endpoint protection and full offline scans are clean, and no unexpected processes are running. A technician finds a small adapter between the keyboard cable and the USB port. What is the MOST likely cause?
- A.A rootkit hiding the collection process
- B.A hardware keylogger capturing keystrokes✓ Answer
- C.Ransomware staging for later encryption
- D.Bloatware transmitting usage telemetry
A hardware keylogger sits inline on the physical keyboard path and records keystrokes before the operating system ever sees them, so no software scanner or process listing can reveal it and physical inspection is the only reliable check. A rootkit would still be software resident on the host, which the offline scan would have had a chance to find.
Source: CompTIA Security+ SY0-701 Obj. 2.4 — malware attacks: keylogger (software and hardware variants)Report a problem with this question
21. A file server shows inaccessible shares, files renamed with an unknown extension, and a ransom note, and the encryption is still spreading to other shares. What should the response team do FIRST?
- A.Restore all shares from the most recent backup
- B.Reimage the affected systems right away
- C.Pay the ransom to obtain the decryption key
- D.Isolate the affected systems from the network to stop the spread✓ Answer
Containment comes before eradication and recovery, so isolating affected hosts is the first step because active encryption keeps consuming data every minute it can still reach shares. Reimaging or restoring first would destroy forensic evidence and simply re-expose clean data to the still-running infection, and paying is not a control and does not guarantee recovery.
Source: CompTIA Security+ SY0-701 Obj. 2.4 (ransomware) and Obj. 2.5 (isolation, segmentation)Report a problem with this question
22. New laptops arrive with vendor-preinstalled trial utilities, toolbars, and media managers that no one uses. They are not malicious by design, but they run services and expand the attack surface. What are they, and what is the correct hardening step?
- A.Trojan; block its traffic at the firewall
- B.Spyware; quarantine it with antivirus
- C.Bloatware; remove unnecessary software as part of hardening✓ Answer
- D.Rootkit; reimage every affected laptop
Bloatware is preinstalled, unwanted vendor software that is not malware but still adds listening services, background processes, and unpatched code to every image. The prescribed control is the hardening technique of removing unnecessary software, typically by building a clean standard image, rather than treating it as an infection to quarantine.
Source: CompTIA Security+ SY0-701 Obj. 2.4 (bloatware) and Obj. 2.5 (hardening: removal of unnecessary software)Report a problem with this question
23. A code review of a C application finds a routine that copies an attacker-controllable string into a fixed 64-byte stack array using strcpy(). Which change most directly eliminates the vulnerability?
- A.Enable full-disk encryption on the server that runs the application
- B.Enlarge the stack array to 1024 bytes so that realistic inputs fit
- C.Validate the input length and use a bounds-checked copy that cannot write past the end of the array✓ Answer
- D.Place a web application firewall in front of the application
A buffer overflow occurs because the copy writes past the allocated buffer into adjacent memory; only bounds checking and input-length validation in the code stop the write itself. Enlarging the buffer merely moves the boundary, a WAF is a compensating control that can be evaded, and disk encryption protects data at rest, not memory safety.
Source: CompTIA Security+ SY0-701 Obj. 2.3 (application vulnerabilities: buffer overflow); CWE-120/CWE-787 (buffer copy without size check / out-of-bounds write)Report a problem with this question
24. A privileged backup script verifies that /var/tmp/report.log is a regular file owned by a standard user, then a moment later opens that path and writes to it. An attacker replaces the path with a symbolic link to a protected system file during the gap between the two operations, and the script overwrites the system file. Which vulnerability does this describe?
- A.Memory injection into the running script
- B.A race condition — time-of-check to time-of-use (TOCTOU)✓ Answer
- C.Directory traversal through an unvalidated path
- D.A buffer overflow in the backup script
The security decision is made at the check, but the state changes before the use, so the validation no longer describes the object being acted on. TOCTOU flaws are fixed with atomic operations or locking — for example, opening the file once and operating on the resulting file descriptor instead of re-resolving the path.
Source: CompTIA Security+ SY0-701 Obj. 2.3 (race conditions: TOC/TOU); CWE-367 time-of-check time-of-use race conditionReport a problem with this question
25. An EDR alert fires on a digitally signed, legitimate browser process that now contains a runtime-allocated executable memory region with no file on disk backing it, and that region is initiating outbound connections to an unknown host. Which technique does this BEST indicate?
- A.A buffer overflow in the browser's parser
- B.A race condition between two browser threads
- C.Memory injection — hostile code placed into the address space of a running, trusted process✓ Answer
- D.Resource reuse of memory released by another tenant
Executable private memory that is not backed by any image on disk, inside an otherwise trusted process, is the classic indicator of code injected directly into that process's memory space. Because nothing is written to disk, signature-based scanning has nothing to inspect, so detection depends on behavior-based EDR and memory analysis.
Source: CompTIA Security+ SY0-701 Obj. 2.3 (memory injection) and 2.4 (indicators); MITRE ATT&CK T1055 Process InjectionReport a problem with this question
26. An organization installs a routine update pulled from its monitoring vendor's official distribution server. The package's digital signature validates correctly, but it contains a backdoor that attackers inserted after compromising the vendor's build pipeline. Which vulnerability category BEST describes the organization's exposure?
- A.A cryptographic vulnerability, because the code-signing algorithm was broken
- B.A misconfiguration of the update client on the endpoints
- C.A supply chain vulnerability at the software provider, delivered as a malicious update✓ Answer
- D.An operating system vulnerability on the systems that installed the package
The signature validated because the attacker subverted the build process before signing, so the weakness is the trust the customer inherits from the software provider, not a broken algorithm. Mitigation therefore relies on vendor risk assessment, staged rollout into a test environment, and behavior monitoring of updated hosts rather than on signature checking alone.
Source: CompTIA Security+ SY0-701 Obj. 2.3 (supply chain: software provider; malicious update); NIST SP 800-161 (C-SCRM)Report a problem with this question
27. A login page builds its query by concatenating the submitted username directly into a SQL statement. Which remediation BEST eliminates the SQL injection risk?
- A.Rewrite the data access layer to use parameterized queries (prepared statements) with server-side input validation✓ Answer
- B.Deploy a web application firewall with SQL injection signatures in front of the site
- C.Require TLS so that submitted credentials are encrypted in transit
- D.Filter the input against a deny list of SQL keywords such as UNION, SELECT and DROP
Parameterization separates code from data: the query structure is fixed before user input is bound, so input can never be parsed as SQL syntax. A WAF is a compensating control that encoding tricks can bypass, keyword deny lists are always incomplete, and TLS protects confidentiality in transit without changing how the query is assembled.
Source: CompTIA Security+ SY0-701 Obj. 2.3 (web-based: SQLi) and 2.5; OWASP SQL Injection Prevention Cheat Sheet (primary defense: prepared statements)Report a problem with this question
28. An attacker posts a support-portal comment containing a script tag. Every agent who later opens that ticket unknowingly sends their session cookie to an external server. Which attack is this?
- A.SQL injection
- B.Stored (persistent) cross-site scripting✓ Answer
- C.Reflected cross-site scripting
- D.Cross-site request forgery (CSRF)
The payload is saved in the application's own data store and then served to every later viewer, where it executes in their browser under the site's origin and can read non-HttpOnly cookies. Reflected XSS would instead require each victim to follow a crafted link; the defenses here are contextual output encoding, input validation, a Content Security Policy, and HttpOnly session cookies.
Source: CompTIA Security+ SY0-701 Obj. 2.3 (web-based: XSS); OWASP Cross Site Scripting Prevention Cheat SheetReport a problem with this question
29. While a user is logged into an online banking session, they open an unrelated malicious page that silently submits a hidden form to the bank's funds-transfer endpoint. The browser attaches the user's session cookie and the transfer succeeds. Which control BEST prevents this?
- A.HTML-encode all output rendered by the banking application
- B.Convert the transfer query into a parameterized statement
- C.Enforce HTTPS with HSTS on the banking domain
- D.Require a unique, unpredictable anti-CSRF token on every state-changing request and set session cookies to SameSite✓ Answer
CSRF works because the browser automatically attaches the session cookie to any request aimed at the bank, so the server cannot tell the forged request from a real one. A per-session token that the attacker's site can neither read nor predict proves the request originated in the application's own interface; output encoding addresses XSS, parameterization addresses SQLi, and TLS addresses interception.
Source: CompTIA Security+ SY0-701 Obj. 2.4 (forgery/CSRF) and 2.5; OWASP CSRF Prevention Cheat Sheet (synchronizer token pattern)Report a problem with this question
30. A web server log contains: GET /download?doc=..%2f..%2f..%2fetc%2fpasswd — returned with status 200. Which attack does this entry indicate?
- A.Reflected cross-site scripting
- B.Directory traversal using encoded ../ sequences to escape the web root✓ Answer
- C.An on-path attack against the download session
- D.SQL injection against the document database
%2f is a URL-encoded forward slash, so the parameter contains repeated ../ sequences that walk the file path above the web root, and the 200 response suggests the file was actually returned. The fix is to canonicalize and validate the resolved path against an allow list (or reference files by ID rather than name) and to run the web process with least privilege.
Source: CompTIA Security+ SY0-701 Obj. 2.4 (application attacks: directory traversal); CWE-22 path traversalReport a problem with this question
31. A network-tools web page passes the value of the 'host' field straight to an operating system shell that runs ping. A tester enters 10.0.0.5; id and receives the output of the id command. Which remediation BEST addresses the root cause?
- A.HTML-encode the command output before displaying it on the page
- B.Use parameterized SQL queries for the tool's logging database
- C.Invoke the utility through a language API or a parameterized process call with no shell, and validate the input against a strict allow list of permitted characters✓ Answer
- D.Rate-limit the page so that only ten diagnostics can run per minute
The injection succeeds because user data is concatenated into a shell command string where ';' is a command separator; removing the shell and allow-listing the permitted characters keeps the input from ever being interpreted as a command. Encoding the output, parameterizing an unrelated SQL query, and rate limiting all leave the injection path fully intact.
Source: CompTIA Security+ SY0-701 Obj. 2.4 (injection attacks) and 2.5 (input validation); CWE-78 OS command injectionReport a problem with this question
32. A manufacturing HMI runs an operating system the vendor no longer supports; no patches will ever be issued, and the control system cannot be replaced for several years. Which is the BEST mitigation?
- A.Isolate the HMI in a segmented zone with strict ACLs, allow only required protocols through a jump server, and monitor it closely✓ Answer
- B.Install consumer antivirus on the HMI and let it update its definitions directly from the internet
- C.Connect the HMI to the corporate network so it can receive centralized patch management
- D.Install operating system patches from a third-party community repository
End-of-life means the vendor issues no patches, so the risk must be reduced by shrinking exposure rather than by patching — segmentation, isolation, restrictive ACLs, and monitoring are the standard compensating controls for unpatchable ICS and legacy assets. Unofficial patches are unvalidated on control equipment, and giving the HMI broader network connectivity increases its attack surface instead of reducing it.
Source: CompTIA Security+ SY0-701 Obj. 2.3 (hardware: end-of-life, legacy) and 2.5 (segmentation, isolation, compensating controls); NIST SP 800-82 (ICS security)Report a problem with this question
33. A researcher extracts a private key from a hardware token by measuring tiny variations in its power draw and in how long each operation takes, without finding any mathematical weakness in the algorithm itself. Which attack is this?
- A.An exhaustive brute-force search of the key space
- B.A birthday attack
- C.A downgrade attack
- D.A side-channel attack✓ Answer
A side-channel attack exploits physical or implementation leakage — timing, power consumption, electromagnetic emissions, or cache behavior — rather than any weakness in the algorithm's mathematics. Countermeasures are implementation-level: constant-time operations, blinding, and physical shielding or noise injection.
Source: CompTIA Security+ SY0-701 Obj. 2.3 (hardware and cryptographic vulnerabilities); FIPS 140-3 non-invasive (side-channel) attack mitigationReport a problem with this question
34. A scan finds dozens of internet-reachable embedded controllers and cameras whose vendor default administrator passwords are unchanged and whose management ports are open to the internet. Which action BEST remediates the exposure?
- A.Enable an account lockout policy after five failed logins on each device
- B.Schedule quarterly credentialed vulnerability scans of the device subnet
- C.Change the default credentials, enforce a hardened configuration baseline, and close or restrict the management ports to an internal management network✓ Answer
- D.Purchase cyber liability insurance to cover losses from device compromise
Vendor default passwords are published, so an attacker authenticates on the first attempt and a lockout threshold never triggers. The vector is removed only by configuration enforcement — changing defaults, applying a hardened baseline, and closing or restricting unnecessary service ports; scanning is detective and insurance merely transfers residual risk.
Source: CompTIA Security+ SY0-701 Obj. 2.2 (open service ports, default credentials) and 2.5 (configuration enforcement; hardening: change default passwords, disable ports/protocols)Report a problem with this question
35. A researcher downloads customer files from a company's cloud object storage container without authenticating. The cloud platform is operating exactly as designed and no provider flaw is involved. What is the root cause?
- A.Weak encryption of the data at rest
- B.A customer-side misconfiguration of the storage container's access policy✓ Answer
- C.A VM escape performed by another tenant on the same host
- D.A zero-day vulnerability in the provider's hypervisor
Under the shared responsibility model the customer, not the provider, configures access control on its own data, so an anonymously readable container policy is a customer misconfiguration — the most common root cause of cloud data exposure. Server-side encryption at rest would not have helped, because the platform transparently decrypts objects for any request the policy authorizes.
Source: CompTIA Security+ SY0-701 Obj. 2.3 (cloud-specific vulnerabilities; misconfiguration); cloud shared responsibility modelReport a problem with this question
36. A tenant provisions a new virtual machine in a public cloud and finds fragments of another organization's data in the storage and memory allocated to it. Which vulnerability does this illustrate?
- A.Side loading of an unauthorized machine image
- B.VM escape from the guest to the hypervisor
- C.A race condition in the provisioning workflow
- D.Resource reuse — memory or storage reallocated to a new tenant without being sanitized✓ Answer
Resource reuse is the exposure of residual data left behind when memory or storage is recycled to a different tenant without sanitization. VM escape is a different flaw entirely — it means breaking out of the guest to reach the hypervisor or other guests — and here no isolation boundary was broken; mitigation is provider-side zeroing of reclaimed resources plus tenant-side encryption with customer-managed keys.
Source: CompTIA Security+ SY0-701 Obj. 2.3 (virtualization: VM escape, resource reuse); NIST SP 800-88 (media sanitization principles)Report a problem with this question
37. An attacker positioned in the traffic path repeatedly interferes with the TLS handshake until the client and server agree on an obsolete protocol version and an export-grade cipher that the attacker can decrypt. Which mitigation BEST addresses this?
- A.Disable legacy protocol versions and weak cipher suites on the server so that no fallback is possible✓ Answer
- B.Increase the session timeout so that fewer handshakes take place
- C.Shorten certificate lifetimes and rotate certificates more frequently
- D.Reissue the server certificate with a longer RSA key while continuing to accept the legacy suites
A downgrade attack can only succeed if the weak options are still negotiable, so removing obsolete versions and weak suites from the server configuration eliminates the choice the attacker is forcing. A longer key, shorter certificate lifetimes, and session timeouts change none of that, because the attacker never has to defeat the strong option — only steer the negotiation away from it.
Source: CompTIA Security+ SY0-701 Obj. 2.4 (cryptographic attacks: downgrade) and 2.5; NIST SP 800-52 Rev. 2 (disable legacy TLS versions and weak cipher suites)Report a problem with this question
38. An attacker produces two different contract documents that hash to the same digest, so a digital signature obtained on the harmless version is also valid on the fraudulent one. Which statement BEST describes what happened?
- A.A rainbow table reversed the digest back into the document text
- B.A downgrade attack forced the signer to use a weaker signature protocol
- C.A preimage attack recovered the original document from its digest
- D.A collision attack defeated the hash function's collision resistance, and the birthday problem makes such pairs findable at roughly the square root of the digest space✓ Answer
A digital signature is computed over the digest, not the document, so any second input with the same digest inherits the signature — that is exactly a break of collision resistance. The birthday problem means collisions appear after roughly 2^(n/2) work rather than 2^n, which is why short digests and legacy hash algorithms are no longer acceptable for signatures.
Source: CompTIA Security+ SY0-701 Obj. 2.4 (cryptographic attacks: collision, birthday); NIST SP 800-107 (collision resistance strength is about half the digest length)Report a problem with this question
39. SIEM correlation shows a single password attempted once per hour against 4,000 distinct user accounts from a rotating set of source addresses, and no account lockouts have triggered. Which attack is in progress?
- A.An offline rainbow table attack against captured password hashes
- B.Credential stuffing using username and password pairs from a previous breach
- C.A brute-force attack against a single privileged account
- D.Password spraying✓ Answer
Password spraying is defined by one (or a few) common passwords tried across many accounts and paced slowly so that no account reaches its lockout threshold — the absence of lockouts is the tell. Brute force sends many passwords at one account and would trip lockout, credential stuffing replays known valid pairs so the passwords would vary, and a rainbow table attack is offline and would generate no authentication logs; the effective defenses are MFA and detection of the one-password/many-accounts pattern.
Source: CompTIA Security+ SY0-701 Obj. 2.4 (password attacks: spraying vs. brute force) and 2.5; NIST SP 800-63B (throttling and MFA for authentication)Report a problem with this question
40. Why does adding a unique random salt to each password before hashing defeat precomputed rainbow tables?
- A.Because the salt encrypts the password so that it can be decrypted later for verification
- B.Because the salt guarantees that no two users can choose the same password
- C.Because the salt slows down every hash computation, which is what makes GPU cracking impractical
- D.Because identical passwords produce different digests, so no table built in advance can cover the salted values✓ Answer
Rainbow tables trade storage for time by precomputing digests for candidate passwords, which only works if the same password always hashes to the same value; a per-user random salt would force the attacker to build a separate table for every salt. Slowing each computation is key stretching (a work factor in bcrypt, PBKDF2, or Argon2) — a complementary but distinct control — and hashing is one-way, not encryption.
Source: CompTIA Security+ SY0-701 Obj. 2.4/2.5 (password attacks and mitigations); NIST SP 800-63B (salting and memory-hard key derivation for stored secrets)Report a problem with this question
41. A legacy internal service authenticates clients with a token that never expires and is transmitted without encryption. An attacker captures a valid authentication exchange and resends it hours later, gaining access without ever learning the password. Which combination BEST mitigates this?
- A.Enable account lockout after five failed authentication attempts
- B.Increase password complexity and require quarterly password changes
- C.Encrypt the session in transit and make each exchange unique with nonces, timestamps, or sequence numbers, combined with mutual authentication✓ Answer
- D.Store the service's password hashes with a stronger algorithm and unique salts
In a replay attack the adversary reuses a message that was already valid, so password strength, lockout thresholds, and hash storage are all irrelevant — nothing is ever guessed. Freshness values such as nonces, timestamps, and sequence numbers make a captured exchange invalid when resent, and transport encryption with mutual authentication prevents the capture in the first place; this is what distinguishes replay from an on-path attack (real-time interception and modification) and from session hijacking (use of a stolen session cookie).
Source: CompTIA Security+ SY0-701 Obj. 2.4 (replay, credential replay) and 2.5 (encryption); NIST SP 800-63B (replay resistance)Report a problem with this question
42. Users on one VLAN report intermittent certificate warnings. On several workstations the ARP cache maps the default gateway IP to the MAC address of an ordinary workstation, and internet-bound traffic is transiting that workstation. Which mitigation BEST addresses the underlying technique?
- A.Increase the ARP cache timeout on all workstations
- B.Deploy a web application firewall in front of the internal web servers
- C.Place a network IDS on a monitoring tap for the VLAN
- D.Enable DHCP snooping and Dynamic ARP Inspection on the access switches so that forged ARP replies are dropped✓ Answer
ARP carries no authentication, so forged replies can bind the gateway IP to the attacker's MAC and place the attacker on the traffic path, which is what produces the certificate warnings. Dynamic ARP Inspection validates every ARP packet against the trusted DHCP snooping binding table at the switch and drops the forgeries; an IDS only detects, a WAF operates at the wrong layer, and a longer ARP cache timeout would prolong the poisoning.
Source: CompTIA Security+ SY0-701 Obj. 2.4 (on-path attacks / ARP poisoning) and 2.5; RFC 826 (ARP has no authentication); switch hardening with DHCP snooping + Dynamic ARP InspectionReport a problem with this question
43. An organization's internet circuit saturates with large DNS response packets arriving from thousands of open resolvers worldwide, all addressed to a host that never sent a query. Which attack is this?
- A.An on-path attack intercepting the organization's DNS traffic
- B.DNS cache poisoning of the organization's resolver
- C.DNS tunneling used to exfiltrate data from the network
- D.A reflected, amplified DDoS attack: the attacker sent small queries with the victim's address spoofed as the source✓ Answer
Reflection means the source address was spoofed so the resolvers' answers land on the victim, and amplification means each small query yields a much larger response, multiplying the bandwidth consumed. Cache poisoning inserts false records and DNS tunneling encodes data inside queries — neither produces a flood of unsolicited responses; upstream source-address validation, scrubbing or anycast capacity, and disabling open recursion are the relevant controls.
Source: CompTIA Security+ SY0-701 Obj. 2.4 (DDoS: amplified, reflected); BCP 38 / RFC 2827 (source address validation)Report a problem with this question
44. Employees in a corporate building connect to an access point that broadcasts the company SSID with a strong signal and presents a portal that harvests their credentials. The device is not owned by the company. Which is the BEST long-term mitigation?
- A.Disable SSID broadcast on the corporate access points
- B.Change the wireless pre-shared key every month
- C.Enable MAC address filtering on the corporate access points
- D.Deploy WPA3-Enterprise/802.1X with clients configured to validate the RADIUS server certificate, and use a wireless IPS to detect rogue access points✓ Answer
An evil twin succeeds because clients identify the network only by its broadcast name, which any attacker can copy; under 802.1X the client can be required to validate the RADIUS server's certificate, so a rogue access point that cannot present the trusted certificate is rejected before credentials are sent. Rotating a pre-shared key, hiding the SSID (still visible in probe and association frames), and MAC filtering (MAC addresses are trivially cloned) do not stop an attacker who simply mimics the network name.
Source: CompTIA Security+ SY0-701 Obj. 2.4 (wireless attacks: evil twin, rogue AP) and 2.5; IEEE 802.1X/EAP server certificate validationReport a problem with this question
Practice questions based on the CompTIA Security+ SY0-701 exam objectives. This is an independent study tool, not affiliated with or endorsed by CompTIA, and does not grant certification. About Security+ →