SY0-701 domain - 22% of the exam

Threats, Vulnerabilities, and Mitigations

Threats, Vulnerabilities, and Mitigations is 22% of the CompTIA Security+ (SY0-701) (SY0-701) exam. These are the objectives it covers, each with practice questions and worked explanations.

Objectives in this domain

Sample question from this domain

Free sampleThreats, Vulnerabilities, and Mitigationseasy

A regional water utility's SCADA network is breached by an attacker who patiently maintains access for months, exfiltrates engineering diagrams, and tampers with no production processes. Forensics traces the operation to infrastructure linked to a foreign military intelligence unit. Which threat actor category best fits the adversary in this incident?

  • AAn organised cybercrime gang motivated by extorting the utility through a ransomware payout demand.
  • BA hacktivist collective protesting the utility's environmental record through public defacement actions.
  • CA disgruntled insider abusing valid credentials to harvest confidential project files for personal use.
  • DA nation-state actor conducting cyber espionage to map critical infrastructure for future leverage. Correct
Recognise that prolonged stealthy intrusions targeting critical infrastructure for intelligence value typically map to nation-state threat actors. Nation-state actors prioritise persistent access, low-noise operations, and intelligence collection over immediate disruption or financial gain. Stealing engineering diagrams from a SCADA environment supports future targeting and strategic leverage, which is the defining motivation of state-sponsored espionage against critical infrastructure operators.

Why A is wrong: Tempting because utilities are common ransomware targets, but the long dwell time, lack of disruption, and theft of engineering diagrams point to espionage rather than financially motivated extortion.

Why B is wrong: Hacktivists seek visibility and publicity for a cause, so they would deface sites or leak data publicly rather than quietly steal schematics for months.

Why C is wrong: An insider scenario is plausible at utilities, but forensics here points to external foreign infrastructure rather than a current employee acting from within the network.

Why D is correct: Long-term stealthy access, theft of engineering data, and attribution to a foreign military intelligence unit are hallmarks of nation-state espionage against critical infrastructure.

Other domains in this exam

See also the SY0-701 cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.