Comptia Security+ Domain 2

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/145

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:39 AM on 9/18/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

146 Terms

1
New cards

What is a threat actor?

An individual, group, or entity responsible for activity that negatively affects another entity's security. Also called a malicious actor.

2
New cards

What characteristics help identify a threat actor?

Internal vs. external, resources/funding, sophistication/capability, and motivation.

3
New cards

What is an APT?

Advanced Persistent Threat - a highly capable attacker that maintains long-term access and conducts targeted operations. Often associated with nation-states.

4
New cards

What characteristics suggest a nation-state attacker?

Massive funding/resources, very high sophistication, long-term objectives, espionage, disruption, warfare, or strategic data theft.

5
New cards

What is an unskilled attacker?

An attacker using premade tools/scripts with limited technical understanding and little funding.

6
New cards

What is a hacktivist?

An attacker motivated primarily by ideology, political/philosophical beliefs, revenge, or disruption.

7
New cards

What makes an insider threat dangerous?

The attacker already has legitimate access, organizational knowledge, and potentially trusted credentials/resources.

8
New cards

What motivation is most strongly associated with organized crime?

Financial gain. Organized criminal groups can also have substantial funding and sophistication.

9
New cards

What is Shadow IT?

Technology, cloud services, applications, or infrastructure deployed outside the organization's approved IT processes.

10
New cards

Why is Shadow IT a security problem even if users aren't malicious?

IT/security may not know the system exists, so it may lack approved security configurations, monitoring, patching, or data protections.

11
New cards

What is a threat/attack vector?

The method or path an attacker uses to gain access to or compromise a target.

12
New cards

What are common message-based threat vectors?

Malicious email, SMS, instant messages, links, attachments, and social engineering messages.

13
New cards

Why can image-based attacks be difficult to detect?

Images and formats such as SVG may contain active content or malicious scripts that are less obvious than plain text.

14
New cards

Why are compressed files such as ZIP/RAR useful to attackers?

They can conceal multiple malicious files and may bypass simple inspection mechanisms.

15
New cards

What risk do malicious Office documents often introduce?

Macros, scripts, or malicious add-ins that execute code.

16
New cards

What is vishing?

Voice phishing - social engineering conducted through phone calls or voicemail.

17
New cards

What is smishing?

SMS phishing - phishing delivered through text messages.

18
New cards

What is phishing?

Social engineering, often combined with spoofing, designed to trick victims into revealing information, clicking links, or executing malicious content.

19
New cards

What is Business Email Compromise (BEC)?

An attacker impersonates or compromises a trusted business identity to manipulate employees, commonly into making fraudulent payments or wire transfers.

20
New cards

CEO requests an urgent secret wire transfer to a new bank account. What should you suspect?

Business Email Compromise / CEO fraud.

21
New cards

What is typosquatting?

Registering domains resembling legitimate domains by using misspellings or typing mistakes to mislead users.

22
New cards

What is pretexting?

Creating a believable fabricated story or identity to convince a victim to provide information or take an action.

23
New cards

Pretexting vs. impersonation?

Pretexting = fabricated scenario/story. Impersonation = pretending to be another person/entity. They frequently work together.

24
New cards

What is elicitation?

Using conversation and psychological techniques to extract information without the victim realizing they are being interrogated.

25
New cards

What is a watering-hole attack?

Compromising a website frequently visited by the intended victims so attackers can target them indirectly.

26
New cards

Why is a watering-hole attack different from ordinary phishing?

Instead of bringing malicious content directly to the victim, the attacker compromises somewhere the victim already visits.

27
New cards

What is brand impersonation?

Creating fraudulent websites/messages that mimic recognizable brands to gain trust, steal information, or distribute malware.

28
New cards

What is disinformation?

Deliberately distributing false information to deceive or manipulate an audience.

29
New cards

How can removable media bypass network defenses?

USB devices can physically introduce malware or remove data without traffic crossing the normal network perimeter.

30
New cards

Why is a malicious USB especially dangerous to an air-gapped network?

It provides a physical method of transferring malicious code into a network that intentionally lacks external connectivity.

31
New cards

What is a supply-chain attack?

Compromising a vendor, supplier, developer, update process, hardware provider, or other trusted upstream component to reach downstream victims.

32
New cards

Why can an MSP become a valuable attacker target?

A Managed Service Provider may have privileged access to many customers, so compromising one provider can provide access to many networks.

33
New cards

What is memory injection?

Injecting malicious code into the memory space of another running process to hide or inherit that process's privileges.

34
New cards

What is DLL injection?

Injecting/loading a malicious Dynamic-Link Library into another process so malicious code executes as part of that process.

35
New cards

Why would malware inject itself into a legitimate process?

To hide from detection and gain the legitimate process's access rights/permissions.

36
New cards

What is a buffer overflow?

Writing more data into a memory buffer than it can hold, overwriting adjacent memory and potentially causing crashes or code execution.

37
New cards

What coding practice helps prevent buffer overflows?

Bounds checking / proper memory validation.

38
New cards

What is a race condition?

A vulnerability where security or program behavior depends on the timing/order of simultaneous operations.

39
New cards

What is TOCTOU?

Time-of-Check to Time-of-Use - a race condition where something changes between checking a condition and using the result.

40
New cards

A system checks that a file is safe, then an attacker replaces it before the system opens it. What attack?

TOCTOU race condition.

41
New cards

Why can software updates themselves become an attack vector?

Users trust updates. If the vendor/update infrastructure is compromised, malicious code can be delivered as a legitimate update.

42
New cards

What major concept does the SolarWinds incident demonstrate?

Software supply-chain compromise / malicious trusted updates.

43
New cards

What is SQL injection (SQLi)?

Injecting malicious SQL commands through application input so the backend database executes attacker-controlled queries.

44
New cards

What commonly enables SQL injection?

Improper handling/validation of user input and insecure database queries.

45
New cards

' OR '1'='1 appearing in an authentication field suggests what?

SQL injection.

46
New cards

What is XSS?

Cross-Site Scripting - injecting malicious client-side scripts, commonly JavaScript, that execute in another user's browser.

47
New cards

What does XSS primarily exploit: database trust or browser/user trust?

The user's/browser's trust in a legitimate website.

48
New cards

What is reflected XSS?

Malicious script is contained in a request/link and immediately reflected by the vulnerable site into the victim's browser.

49
New cards

What is stored/persistent XSS?

Malicious script is permanently stored on the target application and executes whenever users view the affected content.

50
New cards

Reflected vs. stored XSS?

Reflected: payload arrives with a specific request/link. Stored: payload remains on the server and affects future visitors.

51
New cards

XSS vs. SQL injection?

XSS targets the user's browser/client-side execution. SQLi targets backend database queries.

52
New cards

What is firmware?

Software embedded inside a hardware device that controls its basic functionality.

53
New cards

What is EOL?

End of Life - the vendor stops selling a product; some support may potentially continue.

54
New cards

What is EOSL?

End of Service Life - vendor support and routine updates/security patches have ended.

55
New cards

Why is EOSL usually a bigger security concern than EOL?

Unsupported systems may no longer receive security patches for newly discovered vulnerabilities.

56
New cards

What is a legacy platform?

An older system/application still in use despite outdated technology, limited support, or security limitations.

57
New cards

What is VM escape?

Breaking out of a guest virtual machine and accessing the hypervisor/host or other guest systems.

58
New cards

Why is VM escape extremely dangerous?

Compromising the host can potentially give the attacker influence over multiple guest VMs.

59
New cards

What is the virtualization resource reuse risk?

Physical memory/storage/CPU resources are reused between VMs, creating potential data exposure if resource handling is insecure.

60
New cards

What are common cloud security vulnerabilities?

Weak authentication, unpatched systems, misconfigurations, excessive permissions, exposed data, and vulnerable applications/APIs.

61
New cards

What is an open permission vulnerability?

A resource is configured so unauthorized users can access data or functionality.

62
New cards

Why are unsecured administrative accounts especially dangerous?

Compromise provides powerful privileges capable of changing configurations, accessing data, or controlling the system.

63
New cards

Which is safer: direct root login or using a normal account plus sudo?

A normal account using controlled privilege elevation such as sudo.

64
New cards

Why are default credentials dangerous?

Vendor default usernames/passwords are widely known and can give attackers immediate administrative access.

65
New cards

What famous malware abused default IoT credentials?

Mirai botnet.

66
New cards

Why should unnecessary services and ports be disabled?

Every service/port expands the attack surface and may contain exploitable vulnerabilities or misconfigurations.

67
New cards

Why are Telnet and FTP considered insecure protocols?

They traditionally transmit information without encryption, potentially exposing credentials/data in plaintext.

68
New cards

Secure replacements for Telnet and FTP?

SSH instead of Telnet; SFTP instead of FTP.

69
New cards

What is jailbreaking?

Bypassing Apple's iOS restrictions to gain deeper operating-system access and install unauthorized software.

70
New cards

What is rooting?

Gaining privileged/root-level access to an Android device.

71
New cards

What is sideloading?

Installing an application manually from outside the approved application store/distribution channel.

72
New cards

Why can jailbreaking/rooting weaken MDM protections?

They bypass normal OS security restrictions, allowing users/apps to circumvent controls enforced by MDM.

73
New cards

What is a zero-day vulnerability?

A vulnerability that is unknown to or not yet fixed by the vendor when attackers can exploit it.

74
New cards

Why are zero-days difficult to defend against?

Existing signatures, patches, and known-vulnerability defenses may not yet exist.

75
New cards

What is malware?

Malicious software designed to damage, disrupt, spy, steal, manipulate, or gain unauthorized access.

76
New cards

What is ransomware?

Malware that makes data/resources unavailable, commonly through encryption, and demands payment for restoration.

77
New cards

What is one of the strongest defenses against ransomware impact?

Protected offline/isolated backups, combined with patching and endpoint protection.

78
New cards

What is a virus?

Self-replicating malware that generally requires execution/user activity or a host file/program to spread.

79
New cards

What is a worm?

Malware that self-propagates automatically, commonly across networks without requiring user interaction.

80
New cards

Virus vs. worm?

Virus usually needs execution/host interaction. Worm spreads automatically.

81
New cards

What is fileless malware?

Malware operating primarily in memory rather than installing a traditional malicious executable on disk.

82
New cards

Why can fileless malware evade traditional antivirus?

Traditional AV often relies heavily on scanning malicious files stored on disk.

83
New cards

What is spyware?

Malware that secretly monitors users and collects information such as browsing behavior or credentials.

84
New cards

What is a keylogger?

Software/hardware that records keystrokes, potentially capturing passwords, messages, and sensitive information.

85
New cards

Why can keylogging bypass network encryption?

The keystrokes are captured before the data is encrypted for transmission.

86
New cards

What is a logic bomb?

Malicious code that remains dormant until a predefined condition/event occurs.

87
New cards

What is a time bomb?

A logic bomb triggered by a specific time or date.

88
New cards

What is a rootkit?

Malware designed to hide deeply within a system, often modifying low-level/core system components to conceal itself or maintain privileged access.

89
New cards

Why are rootkits difficult to detect?

A rootkit may manipulate the operating system itself, hiding malicious processes/files from normal monitoring tools.

90
New cards

What is bloatware?

Unnecessary preinstalled software that consumes resources and may increase attack surface.

91
New cards

Why is physical access considered such a major security risk?

An attacker with physical control can potentially bypass many software-based defenses.

92
New cards

What is RFID cloning?

Copying information from an RFID badge/fob to another device/card to impersonate the legitimate holder.

93
New cards

What is an environmental attack/risk?

Disrupting supporting infrastructure such as power, cooling/HVAC, humidity control, or fire suppression.

94
New cards

What is DoS?

Denial of Service - making a system/service unavailable by overwhelming it, exploiting a vulnerability, or disrupting supporting resources.

95
New cards

What is DDoS?

Distributed Denial of Service - many systems coordinate to overwhelm or exhaust a target.

96
New cards

Why are botnets commonly associated with DDoS?

They provide attackers with thousands or millions of compromised devices that can generate traffic simultaneously.

97
New cards

What is DDoS reflection?

Attacker spoofs the victim's address so third-party systems send their replies to the victim.

98
New cards

What is DDoS amplification?

Small attacker requests generate much larger responses toward the victim, multiplying attack traffic.

99
New cards

Which protocols are often associated with reflection/amplification attacks?

Protocols such as DNS and NTP that can generate significant responses and historically lacked strong request authentication.

100
New cards

What is DNS poisoning?

Manipulating DNS information or responses so users are redirected to an incorrect/malicious destination.