SY0-701 domain - 22% of the exam

Threats, Vulnerabilities, and Mitigations

Threats, Vulnerabilities, and Mitigations is 22% of the CompTIA Security+ (SY0-701) exam. These are the objectives it covers, each with practice questions and worked explanations.

Objectives in this domain

Sample question from this domain

Free sampleThreats, Vulnerabilities, and Mitigationseasy

A marketing team frustrated by slow IT procurement signs up for a third-party analytics SaaS using a corporate credit card and uploads customer contact lists to it. The security team only learns about the service after a data protection audit. Which risk category does this situation most directly illustrate?

  • AShadow IT, where business units adopt unsanctioned technology that bypasses security and governance review. Correct
  • BAn advanced persistent threat campaign carried out by a sophisticated external nation-state intrusion set.
  • CA malicious insider deliberately exfiltrating sensitive records to harm the employer's reputation and revenue.
  • DHacktivism in which ideologically driven outsiders pressure the organisation by leaking confidential customer details online.
Identify unsanctioned business adoption of cloud services as shadow IT rather than a malicious insider or external campaign. Shadow IT describes technology adopted without IT or security oversight, often well-intentioned but creating data governance, compliance, and exposure risks. The defining trait is bypassing approved procurement and security review, exactly what the marketing team did when uploading customer data to an unvetted SaaS provider.

Why A is correct: Marketing procured and used a SaaS outside the formal IT process, which is the textbook definition of shadow IT and the source of unmanaged data exposure.

Why B is wrong: APT campaigns involve covert external attackers exploiting systems, not authorised employees openly buying a SaaS subscription with corporate funds for daily marketing tasks.

Why C is wrong: Tempting because data left the perimeter, but the marketing team's intent was operational efficiency rather than sabotage, which distinguishes shadow IT from a malicious insider.

Why D is wrong: No external ideologically motivated party is involved and no public leak has occurred, so the scenario does not match hacktivist behaviour or motivation.

Other domains in this exam

See also the SY0-701 cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.