SY0-701 - Threats, Vulnerabilities, and Mitigations - Section 2.2

Explain common threat vectors and attack surfaces.

Describe how phishing, message-based vectors, vulnerable software, and supply chain weaknesses serve as entry points for attackers, and explain how social engineering manipulates users rather than technology. Recognise how expanding an organisation's attack surface - through new devices, applications, or third-party integrations - increases overall exposure.

phishingmessage-based vectorssupply chainsocial engineeringvulnerable software

Practice question for this objective

Free sampleThreats, Vulnerabilities, and Mitigationsmedium

Which statement best distinguishes a threat vector from an attack surface?

  • AA threat vector is the specific path or method an attacker uses to reach a target, while the attack surface is the sum of all points where an attacker could attempt entry. Correct
  • BA threat vector is the inventory of vulnerable services exposed to the internet, while the attack surface is the chosen exploit code an adversary deploys against a target.
  • CA threat vector is the financial impact of a successful breach, while the attack surface is the technical control set used to reduce that impact.
  • DA threat vector is identical to a threat actor's motivation, while the attack surface refers to the actor's available time and resources.
Distinguish a threat vector (the path of attack) from the attack surface (the totality of exposed entry points). Security architecture treats the attack surface as the enumerable set of exposed assets, services, and human interfaces, and treats a threat vector as a specific route through that surface. Confusing the two leads to poor mitigation choices because reducing the surface and blocking individual vectors require different controls.

Why A is correct: This correctly separates the two ideas: the vector is the route taken (a phishing email, a USB drop, a vulnerable port), while the attack surface is the aggregate of exposed entry points such as services, accounts, and interfaces.

Why B is wrong: This is tempting because both phrases involve exposure and exploitation, but it inverts the definitions: the inventory of exposed services is the attack surface, and exploit code is a payload, not a vector.

Why C is wrong: This conflates risk and controls with vectors and surfaces; impact is a consequence, and controls are mitigations, neither of which fits the doctrinal meanings of these two terms.

Why D is wrong: Motivation and resources describe the threat actor profile, not the vector or the surface, so this answer mislabels actor characteristics as architectural concepts.

See more SY0-701 practice questions, answers explained.

More in this domain

Back to all Threats, Vulnerabilities, and Mitigations objectives, or the SY0-701 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.