SY0-701 Domain 2
Nation-state
A government or state-sponsored group that conducts cyberattacks for political, economic, or military gain.
2. Unskilled attacker
An attacker with limited technical knowledge, often using pre-made tools or scripts for attacks.
3. Hacktivist
An individual or group that uses cyberattacks to promote political or social causes.
4. Insider threat
An attack or threat originating from someone within the organization, such as an employee or contractor.
5. Organized crime
Criminal groups using cyberattacks for financial gain, often employing sophisticated methods and networks.
6. Shadow IT
IT systems or devices used within an organization without approval from the IT department, creating security risks.
7. Internal/external
Distinguishes between threats originating inside (internal) or outside (external) an organization.
8. Resources/funding
Refers to the financial or technical resources available to a threat actor, affecting their attack capabilities.
9. Level of sophistication/capability
Describes the skill level and technical resources available to a threat actor, from low to high sophistication.
10. Data exfiltration
The unauthorized transfer of sensitive data from an organization to an external location.
11. Espionage
The act of spying or gathering confidential information for political or corporate advantage.
12. Service disruption
An attack aimed at making a service unavailable or malfunctioning, often for a denial-of-service attack.
13. Blackmail
Using threats or coercion to obtain money, services, or confidential information from a victim.
14. Financial gain
The motive for cyberattacks aimed at stealing money or financial assets from victims.
15. Philosophical/political beliefs
Attacks motivated by ideological or political goals, often seen with hacktivist groups.
16. Ethical
An attack or action performed with the intention of achieving a perceived good, but often involving illegal or unethical means.
17. Revenge
Cyberattacks driven by personal or professional grievances, often to cause harm or damage.
18. Disruption/chaos
Attacks intended to create confusion, instability, or disorder, often without a clear end goal.
19. War
Cyberattacks used as part of a larger military strategy or conflict between nations.
20. Email (Message-based vector)
Cyberattacks using email to deliver malicious payloads, often via phishing or malicious attachments.
21. Short Message Service (SMS)
Cyberattacks using text messages to trick users into divulging personal information or downloading malicious software.
22. Instant Messaging (IM)
Attacks using instant messaging platforms to deliver phishing attempts or malicious files.
23. Image-based vector
Attacks that exploit image files to deliver malicious payloads when opened or interacted with.
24. File-based vector
Exploits malicious files, such as documents or executables, to infect systems when opened.
25. Voice call (Threat vector)
Attacks conducted over phone calls, often in the form of vishing (voice phishing) or social engineering.
26. Removable device
Using USB drives or other removable media to infect systems with malware or steal data.
27. Vulnerable software (Client-based vs. agentless)
Attacks targeting unpatched or outdated software, including client-based (requires installed software) or agentless (doesn’t require installation) methods.
28. Unsupported systems and applications
Exploiting outdated or unmaintained software that no longer receives security updates.
29. Unsecure networks (Wireless, Wired, Bluetooth)
Attacks targeting poorly secured network connections, including wireless (Wi-Fi), wired, and Bluetooth networks.
30. Open service ports
Exploiting open and unprotected service ports to gain unauthorized access to systems.
31. Default credentials
Using default usernames and passwords on systems or applications to gain unauthorized access.
32. Supply chain
Exploiting vulnerabilities in the supply chain, including managed service providers, vendors, or suppliers.
33. Phishing
A type of social engineering attack where attackers impersonate legitimate entities to steal sensitive information.
34. Vishing
Voice phishing, where attackers impersonate legitimate organizations over the phone to steal personal information.
35. Smishing
SMS phishing, where attackers use text messages to lure victims into revealing sensitive information.
36. Misinformation/disinformation
Deliberately spreading false or misleading information to manipulate public perception or cause confusion.
37. Impersonation
An attack where the attacker pretends to be someone else, often using stolen credentials or forged identities.
38. Business Email Compromise (BEC)
A type of scam where attackers impersonate a company executive to trick employees into transferring money or sensitive data.
39. Pretexting
A social engineering technique where the attacker creates a fabricated story to obtain sensitive information.
40. Watering hole
A targeted attack where the attacker infects a website that a specific group is known to visit, in hopes of infecting their devices.
41. Brand impersonation
When attackers mimic the branding of a legitimate company to trick users into providing sensitive information.
42. Typosquatting
Registering domain names that are similar to popular websites, hoping users will make a typo and visit the malicious site.
43. Memory injection (Application vulnerability)
An attack where malicious code is inserted into the memory of a running application to execute unauthorized actions.
44. Buffer overflow
A vulnerability where more data is written to a buffer than it can handle, potentially allowing an attacker to execute arbitrary code.
45. Race conditions (Application vulnerability)
Exploiting the timing of events to manipulate system operations, such as time-of-check and time-of-use vulnerabilities.
46. Malicious update
An attack where a software update is compromised to deliver malware to an application or system.
47. Structured Query Language injection (SQLi)
Exploiting vulnerabilities in a web application's database by injecting malicious SQL queries.
48. Cross-site scripting (XSS)
Injecting malicious scripts into a website that are then executed in other users' browsers to steal data or perform actions.
49. Firmware (Hardware vulnerability)
Exploiting weaknesses in the firmware of hardware devices to gain unauthorized access or control.
50. End-of-life (Hardware vulnerability)
Devices or software that are no longer supported by manufacturers, making them vulnerable to exploitation.
51. Virtual machine (VM) escape
Exploiting vulnerabilities in virtual environments to escape a VM and access the host system.
52. Side loading (Mobile device vulnerability)
Installing apps from unofficial sources, which can expose a device to malware.
53. Jailbreaking (Mobile device vulnerability)
Removing software restrictions on a mobile device to allow unauthorized apps to run, potentially compromising security.
54. Zero-day
A vulnerability that is unknown to the software vendor and for which no patch or fix has been released yet.
55. Ransomware (Malware attack)
Malware that locks or encrypts files and demands payment for the decryption key.
56. Trojan (Malware attack)
Malicious software disguised as legitimate software, which, once executed, compromises the system.
57. Worm (Malware attack)
A self-replicating program that spreads across networks without user intervention, often causing damage.
58. Spyware (Malware attack)
Software that secretly monitors and collects information from a user’s device without their consent.
59. Bloatware (Malware attack)
Software that is unnecessarily large, often containing hidden malware or excessive features.
60. Virus (Malware attack)
Malicious code that attaches itself to legitimate programs and spreads to other files or systems.
61. Keylogger (Malware attack)
Malware that records keystrokes on a system to capture sensitive information, like passwords.
62. Logic bomb (Malware attack)
Malicious code triggered by a specific event, such as a particular date or action, to cause damage or disruption.
63. Rootkit (Malware attack)
A type of malware designed to hide its presence and provide unauthorized access to a system.
64. Brute force (Physical attack)
An attack where an attacker tries all possible combinations to crack a password or encryption.
65. RFID cloning (Physical attack)
Copying the data from an RFID-enabled device (like a card) to gain unauthorized access.
66. Distributed Denial-of-Service (DDoS)
An attack that floods a system with traffic to overwhelm and shut it down.
67. Amplified DDoS
A type of DDoS attack where the attacker uses a vulnerable server to amplify the attack.
68. Reflected DDoS
A DDoS attack where the attacker uses a third-party server to reflect the attack traffic towards the victim.
69. Domain Name System (DNS) attacks
Attacks targeting DNS infrastructure, such as DNS spoofing or poisoning, to redirect users to malicious sites.
70. Wireless (Network attack)
Exploiting vulnerabilities in wireless networks to intercept or manipulate data.
71. On-path (Network attack)
When an attacker intercepts or alters communications between two parties without their knowledge.
72. Credential replay (Network attack)
An attacker reuses captured login credentials to impersonate a legitimate user.
73. Malicious code (Network attack)
Code designed to disrupt, damage, or gain unauthorized access to a system or network.
74. Injection (Application attack)
Attacks where malicious code is inserted into an application to execute unauthorized commands.
75. Privilege escalation (Application attack)
Exploiting vulnerabilities to gain higher-level privileges or access within an application or system.
76. Directory traversal (Application attack)
Exploiting a web server to gain access to restricted directories by manipulating file paths.
77. Downgrade (Cryptographic attack)
Forcing a system to use weaker encryption protocols to make it easier to break.
78. Collision (Cryptographic attack)
An attack where two different inputs produce the same hash value, undermining the integrity of cryptographic systems.
79. Birthday (Cryptographic attack)
A type of collision attack that exploits the mathematics of hashing to find two inputs with the same hash value.
80. Password spraying (Password attack)
Trying a few common passwords against many accounts to avoid detection from account lockout policies.
81. Brute force (Password attack)
Trying every possible combination of characters to crack a password or encryption.
82. Account lockout (Indicator of malicious activity)
An indicator that an account has been locked due to too many incorrect login attempts, often signaling a brute-force attack.
83. Concurrent session usage (Indicator of malicious activity)
Multiple sessions from a user account being used simultaneously, potentially indicating a compromised account.
84. Blocked content (Indicator of malicious activity)
Access to certain content is blocked, often a result of network security tools detecting malicious activity.
85. Impossible travel (Indicator of malicious activity)
Detecting a user logging in from two geographically distant locations within a short time frame, often signaling account compromise.
86. Resource consumption (Indicator of malicious activity)
A sudden spike in resource usage (CPU, memory) can indicate an attack like a DDoS or malware running on a system.
87. Resource inaccessibility (Indicator of malicious activity)
When important system resources are unavailable or inaccessible, possibly due to an ongoing attack or system compromise.
88. Out-of-cycle logging (Indicator of malicious activity)
Logging activity outside of normal intervals, which may indicate an attacker is attempting to cover their tracks or alter logs.
89. Published/documented (Indicator of malicious activity)
An incident that matches known patterns of attacks that have been previously documented or published.
90. Missing logs (Indicator of malicious activity)
1. Nation-state
A government or state-sponsored group that conducts cyberattacks for political, economic, or military gain.
2. Unskilled attacker
An attacker with limited technical knowledge, often using pre-made tools or scripts for attacks.
3. Hacktivist
An individual or group that uses cyberattacks to promote political or social causes.
4. Insider threat
An attack or threat originating from someone within the organization, such as an employee or contractor.
5. Organized crime
Criminal groups using cyberattacks for financial gain, often employing sophisticated methods and networks.
6. Shadow IT
IT systems or devices used within an organization without approval from the IT department, creating security risks.
7. Internal/external
Distinguishes between threats originating inside (internal) or outside (external) an organization.
8. Resources/funding
Refers to the financial or technical resources available to a threat actor, affecting their attack capabilities.
9. Level of sophistication/capability
Describes the skill level and technical resources available to a threat actor, from low to high sophistication.
10. Data exfiltration
The unauthorized transfer of sensitive data from an organization to an external location.
11. Espionage
The act of spying or gathering confidential information for political or corporate advantage.
12. Service disruption
An attack aimed at making a service unavailable or malfunctioning, often for a denial-of-service attack.
13. Blackmail
Using threats or coercion to obtain money, services, or confidential information from a victim.
14. Financial gain
The motive for cyberattacks aimed at stealing money or financial assets from victims.
15. Philosophical/political beliefs
Attacks motivated by ideological or political goals, often seen with hacktivist groups.
16. Ethical
An attack or action performed with the intention of achieving a perceived good, but often involving illegal or unethical means.
17. Revenge
Cyberattacks driven by personal or professional grievances, often to cause harm or damage.
18. Disruption/chaos
Attacks intended to create confusion, instability, or disorder, often without a clear end goal.
19. War
Cyberattacks used as part of a larger military strategy or conflict between nations.
20. Email (Message-based vector)
Cyberattacks using email to deliver malicious payloads, often via phishing or malicious attachments.
21. Short Message Service (SMS)
Cyberattacks using text messages to trick users into divulging personal information or downloading malicious software.
22. Instant Messaging (IM)
Attacks using instant messaging platforms to deliver phishing attempts or malicious files.
23. Image-based vector
Attacks that exploit image files to deliver malicious payloads when opened or interacted with.
24. File-based vector
Exploits malicious files, such as documents or executables, to infect systems when opened.
25. Voice call (Threat vector)
Attacks conducted over phone calls, often in the form of vishing (voice phishing) or social engineering.
26. Removable device
Using USB drives or other removable media to infect systems with malware or steal data.
27. Vulnerable software (Client-based vs. agentless)
Attacks targeting unpatched or outdated software, including client-based (requires installed software) or agentless (doesn’t require installation) methods.
28. Unsupported systems and applications
Exploiting outdated or unmaintained software that no longer receives security updates.
29. Unsecure networks (Wireless, Wired, Bluetooth)
Attacks targeting poorly secured network connections, including wireless (Wi-Fi), wired, and Bluetooth networks.
30. Open service ports
Exploiting open and unprotected service ports to gain unauthorized access to systems.
31. Default credentials
Using default usernames and passwords on systems or applications to gain unauthorized access.
32. Supply chain
Exploiting vulnerabilities in the supply chain, including managed service providers, vendors, or suppliers.
33. Phishing
A type of social engineering attack where attackers impersonate legitimate entities to steal sensitive information.
34. Vishing
Voice phishing, where attackers impersonate legitimate organizations over the phone to steal personal information.
35. Smishing
SMS phishing, where attackers use text messages to lure victims into revealing sensitive information.
36. Misinformation/disinformation
Deliberately spreading false or misleading information to manipulate public perception or cause confusion.
37. Impersonation
An attack where the attacker pretends to be someone else, often using stolen credentials or forged identities.
38. Business Email Compromise (BEC)
A type of scam where attackers impersonate a company executive to trick employees into transferring money or sensitive data.
39. Pretexting
A social engineering technique where the attacker creates a fabricated story to obtain sensitive information.
40. Watering hole
A targeted attack where the attacker infects a website that a specific group is known to visit, in hopes of infecting their devices.
41. Brand impersonation
When attackers mimic the branding of a legitimate company to trick users into providing sensitive information.
42. Typosquatting
Registering domain names that are similar to popular websites, hoping users will make a typo and visit the malicious site.
43. Memory injection (Application vulnerability)
An attack where malicious code is inserted into the memory of a running application to execute unauthorized actions.
44. Buffer overflow
A vulnerability where more data is written to a buffer than it can handle, potentially allowing an attacker to execute arbitrary code.
45. Race conditions (Application vulnerability)
Exploiting the timing of events to manipulate system operations, such as time-of-check and time-of-use vulnerabilities.
46. Malicious update
An attack where a software update is compromised to deliver malware to an application or system.
47. Structured Query Language injection (SQLi)
Exploiting vulnerabilities in a web application's database by injecting malicious SQL queries.
48. Cross-site scripting (XSS)
Injecting malicious scripts into a website that are then executed in other users' browsers to steal data or perform actions.
49. Firmware (Hardware vulnerability)
Exploiting weaknesses in the firmware of hardware devices to gain unauthorized access or control.
50. End-of-life (Hardware vulnerability)
Devices or software that are no longer supported by manufacturers, making them vulnerable to exploitation.
51. Virtual machine (VM) escape
Exploiting vulnerabilities in virtual environments to escape a VM and access the host system.
52. Side loading (Mobile device vulnerability)
Installing apps from unofficial sources, which can expose a device to malware.
53. Jailbreaking (Mobile device vulnerability)
Removing software restrictions on a mobile device to allow unauthorized apps to run, potentially compromising security.
54. Zero-day
A vulnerability that is unknown to the software vendor and for which no patch or fix has been released yet.
55. Ransomware (Malware attack)
Malware that locks or encrypts files and demands payment for the decryption key.
56. Trojan (Malware attack)
Malicious software disguised as legitimate software, which, once executed, compromises the system.
57. Worm (Malware attack)
A self-replicating program that spreads across networks without user intervention, often causing damage.
58. Spyware (Malware attack)
Software that secretly monitors and collects information from a user’s device without their consent.
59. Bloatware (Malware attack)
Software that is unnecessarily large, often containing hidden malware or excessive features.
60. Virus (Malware attack)
Malicious code that attaches itself to legitimate programs and spreads to other files or systems.
61. Keylogger (Malware attack)
Malware that records keystrokes on a system to capture sensitive information, like passwords.
62. Logic bomb (Malware attack)
Malicious code triggered by a specific event, such as a particular date or action, to cause damage or disruption.
63. Rootkit (Malware attack)
A type of malware designed to hide its presence and provide unauthorized access to a system.
64. Brute force (Physical attack)
An attack where an attacker tries all possible combinations to crack a password or encryption.
65. RFID cloning (Physical attack)
Copying the data from an RFID-enabled device (like a card) to gain unauthorized access.
66. Distributed Denial-of-Service (DDoS)
An attack that floods a system with traffic to overwhelm and shut it down.
67. Amplified DDoS
A type of DDoS attack where the attacker uses a vulnerable server to amplify the attack.
68. Reflected DDoS
A DDoS attack where the attacker uses a third-party server to reflect the attack traffic towards the victim.
69. Domain Name System (DNS) attacks
Attacks targeting DNS infrastructure, such as DNS spoofing or poisoning, to redirect users to malicious sites.
70. Wireless (Network attack)
Exploiting vulnerabilities in wireless networks to intercept or manipulate data.
71. On-path (Network attack)
When an attacker intercepts or alters communications between two parties without their knowledge.
72. Credential replay (Network attack)
An attacker reuses captured login credentials to impersonate a legitimate user.
73. Malicious code (Network attack)
Code designed to disrupt, damage, or gain unauthorized access to a system or network.
74. Injection (Application attack)
Attacks where malicious code is inserted into an application to execute unauthorized commands.
75. Privilege escalation (Application attack)
Exploiting vulnerabilities to gain higher-level privileges or access within an application or system.
76. Directory traversal (Application attack)
Exploiting a web server to gain access to restricted directories by manipulating file paths.
77. Downgrade (Cryptographic attack)
Forcing a system to use weaker encryption protocols to make it easier to break.
78. Collision (Cryptographic attack)
An attack where two different inputs produce the same hash value, undermining the integrity of cryptographic systems.
79. Birthday (Cryptographic attack)
A type of collision attack that exploits the mathematics of hashing to find two inputs with the same hash value.
80. Password spraying (Password attack)
Trying a few common passwords against many accounts to avoid detection from account lockout policies.
81. Brute force (Password attack)
Trying every possible combination of characters to crack a password or encryption.
82. Account lockout (Indicator of malicious activity)
An indicator that an account has been locked due to too many incorrect login attempts, often signaling a brute-force attack.
83. Concurrent session usage (Indicator of malicious activity)
Multiple sessions from a user account being used simultaneously, potentially indicating a compromised account.
84. Blocked content (Indicator of malicious activity)
Access to certain content is blocked, often a result of network security tools detecting malicious activity.
85. Impossible travel (Indicator of malicious activity)
Detecting a user logging in from two geographically distant locations within a short time frame, often signaling account compromise.
86. Resource consumption (Indicator of malicious activity)
A sudden spike in resource usage (CPU, memory) can indicate an attack like a DDoS or malware running on a system.
87. Resource inaccessibility (Indicator of malicious activity)
When important system resources are unavailable or inaccessible, possibly due to an ongoing attack or system compromise.
88. Out-of-cycle logging (Indicator of malicious activity)
Logging activity outside of normal intervals, which may indicate an attacker is attempting to cover their tracks or alter logs.
89. Published/documented (Indicator of malicious activity)
An incident that matches known patterns of attacks that have been previously documented or published.
90. Missing logs (Indicator of malicious activity)
The absence of logs that would normally be recorded, often indicating that an attacker has deleted or tampered with logs.
91. Segmentation
Dividing a network or system into smaller sections to limit the spread of attacks and improve security.
92. Access control
Methods for restricting access to resources or data to authorized users, based on policies and roles.
93. Access control list (ACL)
A list that defines who can access resources, what actions they can perform, and under what conditions.
94. Permissions
Settings that define the type of access a user or group has to a resource, such as read, write, or execute.
95. Application allow list
A security measure that only allows approved applications to run on a system, blocking unapproved ones.
96. Isolation
Separation of different systems or processes to prevent them from affecting each other in case of a compromise.
97. Patching
The process of applying updates to software or systems to fix vulnerabilities and improve security.
98. Encryption
The process of converting data into a format that is unreadable without a decryption key, ensuring data confidentiality.
99. Monitoring
The continuous tracking of system activities, network traffic, and user actions to detect and respond to threats.
100. Least privilege
The practice of granting users only the minimum level of access necessary to perform their job functions.
101. Configuration enforcement
The process of ensuring that systems are configured in a secure manner, following best practices and security policies.
102. Decommissioning
The secure removal or deactivation of old systems or software to reduce vulnerabilities and prevent unauthorized access.
103. Hardening techniques
Methods used to improve the security of a system or network by reducing its attack surface and vulnerabilities.
104. Encryption (Hardening)
Using cryptography to protect data and communications from unauthorized access.
105. Installation of endpoint protection
Installing security software, such as antivirus and anti-malware, on devices to protect them from threats.
106. Host-based firewall
A firewall installed on an individual device to filter incoming and outgoing traffic and block unauthorized access.
107. Host-based intrusion prevention system (HIPS)
A security system that monitors and prevents malicious activities or unauthorized actions on a specific host.
108. Disabling ports/protocols
The practice of turning off unused or unnecessary network ports and protocols to minimize security risks.
109. Default password changes
Changing default passwords on devices or systems to prevent attackers from exploiting common, easily guessed passwords.
110. Removal of unnecessary software
Uninstalling software that is not needed to reduce potential attack surfaces and vulnerabilities.