Security+ Domain 2 Practice Questions: Threats, Vulnerabilities, and Mitigations
40 free CompTIA Security+ SY0-701 practice questions for Domain 2, Threats, Vulnerabilities, and Mitigations, which is about 22% of the exam. Each question has the correct answer and a clear explanation. No account or signup needed.
Last updated August 2026
- Question 1
A specific mid-level finance employee receives a carefully tailored email referencing real internal projects to trick them into wiring funds. Which attack is this?
- AVishing
- BGeneric phishing
- CWhaling
- DSpear phishing
Show answer and explanation
Correct answer: D. Spear phishing
Spear phishing targets a specific individual with personalized details. Whaling specifically targets senior executives, generic phishing is mass and untargeted, and vishing uses voice calls.
- Question 2
Which type of malware self-replicates and spreads across a network on its own, without needing a host file or any user action?
- AVirus
- BSpyware
- CWorm
- DTrojan
Show answer and explanation
Correct answer: C. Worm
A worm self-propagates across systems without user interaction. A virus needs a host file and usually user action to spread, a Trojan disguises itself as legitimate software, and spyware secretly gathers information.
- Question 3
A user downloads what appears to be a free productivity tool, but it secretly installs a backdoor. Which type of malware is this?
- ATrojan horse
- BLogic bomb
- CRansomware
- DWorm
Show answer and explanation
Correct answer: A. Trojan horse
A Trojan disguises malicious functionality inside something that looks legitimate. A worm self-replicates, a logic bomb waits for a trigger condition, and ransomware encrypts files for extortion.
- Question 4
Malicious code is planted in an application and lies dormant until a specific date arrives, then deletes files. What is this called?
- ARootkit
- BLogic bomb
- CWorm
- DKeylogger
Show answer and explanation
Correct answer: B. Logic bomb
A logic bomb is dormant code that triggers when a condition, such as a date, is met. A rootkit hides privileged access, a worm self-spreads, and a keylogger records keystrokes.
- Question 5
Thousands of compromised devices in a botnet simultaneously flood a company website with traffic until it goes offline. Which attack is this?
- ADistributed denial-of-service (DDoS)
- BPrivilege escalation
- COn-path attack
- DPhishing
Show answer and explanation
Correct answer: A. Distributed denial-of-service (DDoS)
A DDoS uses many compromised hosts (a botnet) to overwhelm a target and deny service. An on-path attack intercepts traffic, privilege escalation raises permissions, and phishing is social engineering.
- Question 6
An attacker uses software that systematically tries every possible character combination to guess a password. Which attack is this?
- APhishing
- BSQL injection
- CBrute-force attack
- DPass-the-hash
Show answer and explanation
Correct answer: C. Brute-force attack
A brute-force attack tries every possible combination until it finds the password. Pass-the-hash reuses a captured hash, phishing tricks a user into revealing it, and SQL injection targets a database.
- Question 7
An application accepts more input than a memory buffer can hold, letting an attacker overwrite adjacent memory and run their own code. Which vulnerability is being exploited?
- ACross-site scripting
- BBuffer overflow
- CRace condition
- DSQL injection
Show answer and explanation
Correct answer: B. Buffer overflow
A buffer overflow writes past the bounds of a memory buffer, corrupting adjacent memory and potentially executing attacker code. The other options are distinct web and timing flaws.
- Question 8
A newly deployed network camera is compromised because it was left with the manufacturer default username and password. Which weakness allowed this?
- AAn insider threat
- BDefault or weak credentials (misconfiguration)
- CA zero-day vulnerability
- DA supply chain attack
Show answer and explanation
Correct answer: B. Default or weak credentials (misconfiguration)
Leaving default credentials in place is a configuration weakness that attackers routinely exploit. A zero-day is an unknown, unpatched flaw, a supply chain attack compromises a vendor, and an insider misuses legitimate access.
- Question 9
Attackers compromise a trusted software vendor and insert malware into a routine product update, which then installs on every customer that updates. This is best described as a?
- ABrute-force attack
- BEvil twin attack
- CWatering hole attack
- DSupply chain attack
Show answer and explanation
Correct answer: D. Supply chain attack
A supply chain attack abuses trust in a vendor or supplier to reach their customers. A watering hole compromises a site the target frequents, brute force guesses credentials, and an evil twin is a rogue wireless access point.
- Question 10
An attacker phones an employee, pretends to be IT support, and convinces them to read out their password. Which social engineering technique is this?
- ASmishing
- BTailgating
- CWhaling
- DVishing
Show answer and explanation
Correct answer: D. Vishing
Vishing is voice phishing, carried out over a phone call. Smishing uses SMS text messages, whaling targets executives, and tailgating is following someone through a secure door.
- Question 11
A security team attributes a months-long, low-and-slow intrusion to a foreign government seeking intellectual property. Which threat actor best matches this profile?
- AHacktivist
- BNation-state actor
- CScript kiddie
- DInsider threat
Show answer and explanation
Correct answer: B. Nation-state actor
Nation-state actors often pursue espionage with advanced, persistent campaigns. Script kiddies use basic tools for notoriety, hacktivists act for ideology or publicity, and insiders abuse legitimate internal access rather than foreign-directed campaigns.
- Question 12
Attackers deface a company website and leave political slogans, with no attempt to steal money or data. What is the most likely motivation?
- AFinancial gain
- BEspionage
- CIdeological
- DBlackmail
Show answer and explanation
Correct answer: C. Ideological
Defacement with political messaging points to ideological or hacktivist motives. Financial gain seeks profit, espionage seeks secrets, and blackmail pressures victims with threats rather than public slogan-based vandalism.
- Question 13
An unskilled attacker downloads a public exploit kit and runs it against random Internet hosts. Which threat actor type is this?
- AOrganized crime
- BCompetitor
- CAdvanced persistent threat
- DUnskilled attacker
Show answer and explanation
Correct answer: D. Unskilled attacker
Unskilled attackers rely on ready-made tools without deep expertise. Organized crime runs coordinated profit schemes, APTs run sophisticated long-term operations, and competitors focus on business advantage, not random mass scanning.
- Question 14
A ransomware gang encrypts hospital systems and demands cryptocurrency, treating attacks as a business. Which threat actor best fits?
- AOrganized crime
- BHacktivist
- CShadow IT user
- DNation-state spy
Show answer and explanation
Correct answer: A. Organized crime
Profit-driven ransomware operations align with organized crime. Hacktivists pursue causes, shadow IT is unauthorized internal tooling, and nation-state spying prioritizes intelligence over public extortion business models.
- Question 15
Which attribute most clearly distinguishes an advanced persistent threat from a casual opportunistic attacker?
- ATargeting only social media accounts
- BAlways demanding a ransom payment
- CLong-term stealthy presence in the environment
- DUse of any form of malware
Show answer and explanation
Correct answer: C. Long-term stealthy presence in the environment
APTs emphasize prolonged, stealthy access and goals. Malware use is common to many actors, social media focus is not defining, and ransom demands describe criminal extortion more than every APT campaign.
- Question 16
After a public controversy, anonymous groups claim responsibility for leaking internal emails to damage the brand. Which actor type fits best?
- AScript kiddie
- BHacktivist
- CData owner
- DInsider threat
Show answer and explanation
Correct answer: B. Hacktivist
Public, cause-driven leaks to shame an organization are classic hacktivism. Insiders already have access but the claim and activism frame matter, script kiddies lack this political purpose, and data owners manage classification, not attacks.
- Question 17
An executive receives a fake invoice email that appears to come from the CFO and authorizes a large wire transfer. Which attack is this?
- ADNS poisoning
- BCredential stuffing
- CWatering hole attack
- DBusiness email compromise
Show answer and explanation
Correct answer: D. Business email compromise
BEC uses impersonation of executives or vendors to drive fraudulent payments. Watering holes compromise sites users trust, credential stuffing replays leaked passwords, and DNS poisoning redirects name resolution.
- Question 18
Employees visit an industry news site that attackers compromised to serve malware only to that company's visitors. What attack is this?
- AWatering hole
- BTyposquatting
- CPass-the-hash
- DWhaling
Show answer and explanation
Correct answer: A. Watering hole
A watering hole infects a site the target group already visits. Whaling targets executives with email fraud, typosquatting registers lookalike domains, and pass-the-hash reuses NTLM hashes for authentication.
- Question 19
A user mistypes a bank URL and lands on a lookalike domain that harvests credentials. Which vector was used?
- ABluejacking
- BDirectory traversal
- CARP spoofing
- DTyposquatting
Show answer and explanation
Correct answer: D. Typosquatting
Typosquatting relies on similar domain names that catch typing errors. Bluejacking sends unsolicited Bluetooth messages, ARP spoofing poisons local LAN mappings, and directory traversal reads files outside web roots.
- Question 20
An attacker leaves infected USB drives in a company parking lot, hoping staff plug them into workstations. Which vector is this?
- AOn-path network interception
- BRemovable media
- CRemote code execution via API
- DCross-site scripting
Show answer and explanation
Correct answer: B. Removable media
USB baiting abuses removable media as the entry path. API RCE is remote software abuse, on-path attacks intercept network traffic, and XSS injects scripts into web pages.
- Question 21
A coffee shop guest creates a free Wi-Fi SSID that matches the cafe name and captures logins. What is this attack?
- ASession fixation
- BWar driving
- CMAC flooding
- DEvil twin
Show answer and explanation
Correct answer: D. Evil twin
An evil twin is a rogue access point mimicking a legitimate SSID. War driving maps wireless networks, MAC flooding overwhelms switch CAM tables, and session fixation forces a known session ID on a victim.
- Question 22
An attacker watches a user type a PIN at a kiosk without the user's knowledge. Which technique is this?
- ADumpster diving
- BHoax
- CPretexting
- DShoulder surfing
Show answer and explanation
Correct answer: D. Shoulder surfing
Shoulder surfing is direct observation of secrets. Dumpster diving recovers discarded documents, pretexting invents a story to extract information, and a hoax spreads false warnings without necessarily watching input.
- Question 23
Attackers try a few common passwords against thousands of accounts to avoid lockouts. Which attack is this?
- APassword spraying
- BDictionary attack on one account
- CBirthday attack
- DRainbow table attack
Show answer and explanation
Correct answer: A. Password spraying
Password spraying uses few passwords across many accounts. Classic dictionary attacks hammer one account with many words, rainbow tables reverse unsalted hashes offline, and birthday attacks target hash collisions.
- Question 24
A web app builds file paths from user input and lets an attacker read /etc/passwd by inserting ../ sequences. Which vulnerability is this?
- AXML external entity
- BRace condition
- CDirectory traversal
- DCross-site request forgery
Show answer and explanation
Correct answer: C. Directory traversal
Directory traversal escapes the intended directory with path tricks. XXE abuses XML entity resolution, CSRF forces unwanted authenticated requests, and race conditions exploit timing between concurrent operations.
- Question 25
An application checks a file's permissions, then an attacker swaps the file before it is opened. Which vulnerability class is this?
- APointer dereference
- BTime-of-check to time-of-use
- CInteger overflow
- DSide-channel leak
Show answer and explanation
Correct answer: B. Time-of-check to time-of-use
TOCTOU races the gap between validation and use. Integer overflow wraps numeric values, pointer dereference mishandles null or invalid pointers, and side channels leak secrets via timing or power.
- Question 26
A guest virtual machine breaks isolation and executes code on the underlying hypervisor host. What vulnerability was exploited?
- AResource pooling
- BVM escape
- CLive migration
- DContainer sprawl
Show answer and explanation
Correct answer: B. VM escape
VM escape crosses the guest-to-host boundary. Sprawl is uncontrolled growth of instances, resource pooling is a cloud design trait, and live migration moves VMs without inherently breaking isolation.
- Question 27
A server still runs an OS that the vendor no longer supports with security updates. Which vulnerability does this represent?
- AEnd-of-life system
- BImproper certificate pinning
- COpen wireless encryption
- DMissing input validation only
Show answer and explanation
Correct answer: A. End-of-life system
Unsupported end-of-life systems cannot receive patches and remain exposed. Certificate pinning issues affect TLS clients, open wireless is a network crypto problem, and input validation flaws are a different software class.
- Question 28
Developers hard-code a shared database password inside a mobile app package that anyone can decompile. Which vulnerability is this?
- AReplay attack
- BHardcoded credentials
- CVLAN hopping
- DMemory injection
Show answer and explanation
Correct answer: B. Hardcoded credentials
Secrets embedded in client packages are hardcoded credentials. Memory injection places code into processes, replay resubmits captured traffic, and VLAN hopping abuses switch tagging on LANs.
- Question 29
A cloud storage bucket holding customer exports is left publicly listable by mistake. Which vulnerability best describes this?
- ABluejacking
- BFirmware rootkit
- CBuffer overflow
- DMisconfiguration
Show answer and explanation
Correct answer: D. Misconfiguration
Public cloud buckets are a classic misconfiguration. Rootkits hide in firmware or OS layers, buffer overflows corrupt memory, and bluejacking is a Bluetooth messaging nuisance, not storage ACL errors.
- Question 30
SIEM alerts show a user authenticating from New York and Tokyo within ten minutes. Which indicator is this?
- ABeaconing
- BMAC address spoofing
- CCertificate expiration
- DImpossible travel
Show answer and explanation
Correct answer: D. Impossible travel
Impossible travel flags authentications too far apart for realistic movement. Beaconing is periodic C2 callbacks, MAC spoofing fakes hardware addresses, and certificate expiration is a PKI lifecycle issue.
- Question 31
Network sensors detect a host sending brief HTTPS connections to the same rare domain every five minutes for days. What does this most suggest?
- ACommand-and-control beaconing
- BSMTP relay misconfiguration
- CDHCP starvation
- DLegitimate certificate renewal
Show answer and explanation
Correct answer: A. Command-and-control beaconing
Regular, low-volume callbacks to an unusual domain often indicate C2 beaconing. Certificate renewal is not typically a multi-day fixed interval pattern, SMTP relay issues affect mail flow, and DHCP starvation exhausts IP leases.
- Question 32
An analyst finds security event logs on a server were cleared shortly after a suspicious service was installed. Why is this concerning?
- AIt shows encryption at rest is working
- BIt proves the patch cycle is healthy
- CIt confirms a successful vulnerability scan
- DIt may indicate anti-forensics after compromise
Show answer and explanation
Correct answer: D. It may indicate anti-forensics after compromise
Clearing logs after suspicious changes is a common anti-forensics indicator. Patch health, scan success, and encryption at rest do not explain deliberate log deletion timed with new services.
- Question 33
Outbound DNS queries contain unusually long subdomain labels with high entropy toward an external domain. What activity is most likely?
- AARP cache poisoning on the LAN
- BNormal recursive resolver caching
- CData exfiltration via DNS tunneling
- DSuccessful SPF validation
Show answer and explanation
Correct answer: C. Data exfiltration via DNS tunneling
Long, high-entropy DNS labels often hide exfiltrated data in tunnels. Resolver caching is normal and short-lived, ARP poisoning is Layer 2 spoofing, and SPF only authenticates email senders.
- Question 34
Host telemetry shows a user's browser spawning PowerShell that downloads a remote script and disables Windows Defender. What is the best classification?
- AMalicious script execution indicator
- BSecure boot attestation success
- CHardware token enrollment
- DExpected browser update behavior
Show answer and explanation
Correct answer: A. Malicious script execution indicator
Browser-to-PowerShell download and security product disablement are strong malware execution indicators. Browser updates, secure boot success, and token enrollment do not match this process chain.
- Question 35
File integrity monitoring reports unexpected changes to system binaries and a new scheduled task running at logon. What should the analyst suspect?
- ANormal NTP clock skew
- BPersistence after endpoint compromise
- CRoutine disk defragmentation
- DSuccessful data classification
Show answer and explanation
Correct answer: B. Persistence after endpoint compromise
Altered system binaries plus logon tasks are classic persistence indicators. Defragmentation, classification labels, and NTP skew do not rewrite critical binaries or add attacker-style scheduled tasks.
- Question 36
Developers add server-side checks that reject unexpected characters in form fields before processing. Which mitigation is this?
- ADisk encryption
- BJob rotation
- CNetwork segmentation
- DInput validation
Show answer and explanation
Correct answer: D. Input validation
Input validation blocks malformed or malicious data at entry. Segmentation isolates networks, disk encryption protects stored data, and job rotation is a personnel control against fraud, not request filtering.
- Question 37
An administrator disables SMBv1 and blocks unused high-risk ports on servers after a threat briefing. What mitigation approach is this?
- AHardening by reducing exposed services
- BPurchasing cyber insurance
- CImplementing steganography
- DCreating a memorandum of understanding
Show answer and explanation
Correct answer: A. Hardening by reducing exposed services
Turning off outdated protocols and unused ports hardens systems and shrinks exposure. Insurance transfers financial risk, MOUs set cooperation intent, and steganography hides messages rather than securing servers.
- Question 38
Security policy forces browsers to open untrusted downloads only inside a restricted virtual desktop with no access to corporate file shares. Which technique is this?
- AKey escrow
- BTokenization
- CLoad balancing
- DIsolation
Show answer and explanation
Correct answer: D. Isolation
Running risky content in a sealed environment is isolation. Load balancing spreads traffic, tokenization replaces sensitive values with surrogates, and key escrow stores cryptographic keys with a trusted party.
- Question 39
To stop malware that spreads through macros, the team configures Office so macros from the Internet are blocked by default. Which mitigation is this?
- AWarm site recovery
- BConfiguration enforcement
- CHomomorphic encryption
- DVLAN hopping prevention
Show answer and explanation
Correct answer: B. Configuration enforcement
Blocking dangerous application features by policy is configuration enforcement, one of the SY0-701 mitigation techniques. VLAN hopping is a network attack, homomorphic encryption computes on ciphertext, and warm sites support disaster recovery capacity.
- Question 40
After detecting malware on a laptop, responders remove it from the LAN and place it on a forensic analysis VLAN. What mitigation step is this?
- AContainment through quarantine
- BTabletop exercise
- CRisk acceptance
- DCertificate pinning
Show answer and explanation
Correct answer: A. Containment through quarantine
Isolating an infected host is containment via quarantine. Tabletop exercises practice response verbally, risk acceptance leaves risk untreated, and certificate pinning validates TLS certificates in clients.
Master every domain
A free account opens all of Domain 1: a lesson, a hands-on lab and a graded question bank on every objective, plus a placement check and a dated plan. No card.
FAQ
Are these Security+ Domain 2 practice questions free?
Yes. Every question on this page is free, with the correct answer and an explanation. No account, payment, or download is required.How much of the Security+ exam is Domain 2?
Domain 2, Threats, Vulnerabilities, and Mitigations, accounts for about 22% of the CompTIA Security+ SY0-701 exam.
Practice another domain
Original practice questions aligned to the CompTIA Security+ SY0-701 objectives. CompTIA and Security+ are trademarks of CompTIA, used here for identification only.