SY0-701 - Threats, Vulnerabilities, and Mitigations (22% of the exam) - Section 2.2

Explain common threat vectors and attack surfaces.

Describe how phishing, message-based vectors, vulnerable software, and supply chain weaknesses serve as entry points for attackers, and explain how social engineering manipulates users rather than technology. Recognise how expanding an organisation's attack surface - through new devices, applications, or third-party integrations - increases overall exposure.

phishingmessage-based vectorssupply chainsocial engineeringvulnerable software

Practice question for this objective

Free sampleThreats, Vulnerabilities, and Mitigationsmedium

Which statement best distinguishes a threat vector from an attack surface?

  • AA threat vector is the specific path or method an attacker uses to reach a target, while the attack surface is the sum of all points where an attacker could attempt entry. Correct
  • BA threat vector is the inventory of vulnerable services exposed to the internet, while the attack surface is the chosen exploit code an adversary deploys against a target.
  • CA threat vector is the financial impact of a successful breach, while the attack surface is the technical control set used to reduce that impact.
  • DA threat vector is identical to a threat actor's motivation, while the attack surface refers to the actor's available time and resources.
Distinguish a threat vector (the path of attack) from the attack surface (the totality of exposed entry points). Security architecture treats the attack surface as the enumerable set of exposed assets, services, and human interfaces, and treats a threat vector as a specific route through that surface. Confusing the two leads to poor mitigation choices because reducing the surface and blocking individual vectors require different controls.

Why A is correct: This correctly separates the two ideas: the vector is the route taken (a phishing email, a USB drop, a vulnerable port), while the attack surface is the aggregate of exposed entry points such as services, accounts, and interfaces.

Why B is wrong: This is tempting because both phrases involve exposure and exploitation, but it inverts the definitions: the inventory of exposed services is the attack surface, and exploit code is a payload, not a vector.

Why C is wrong: This conflates risk and controls with vectors and surfaces; impact is a consequence, and controls are mitigations, neither of which fits the doctrinal meanings of these two terms.

Why D is wrong: Motivation and resources describe the threat actor profile, not the vector or the surface, so this answer mislabels actor characteristics as architectural concepts.

See more SY0-701 practice questions, answers explained.

Exam traps in Threats, Vulnerabilities, and Mitigations

Answers that look right on this material and are not. Each one is a distractor from a different question in the SY0-701 bank for this domain.

  • Enabling verbose application logging on the production servers so that any malicious dependency behaviour is recorded after release

    Why it is wrong: Verbose logging aids post-incident investigation and is a sound practice, but it records behaviour only after a poisoned package has already shipped, so it does not reduce the attack surface at ingestion time.

  • A vishing campaign that relies on a live voice conversation to extract credentials directly from the targeted reception staff.

    Why it is wrong: Vishing is tempting because it is also impersonation-based social engineering, but it specifically uses voice calls, whereas this incident uses text messages and a web link.

  • Generic bulk phishing relying on a high message volume to find a small percentage of willing victims across the recipient base.

    Why it is wrong: Bulk phishing is tempting because the lure is still email-based, but it does not personalise content to named individuals or reference a victim's real client portfolio; this campaign is clearly targeted.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.