2.0 Threats, Vulnerabilities, and Mitigations SY0-701 Practice Quiz

446 exam-style questions covering 22% of the SY0-701 exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the CompTIA Security+ practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

Which of the following BEST characterizes a nation-state threat actor?
  • A. A lone hacker motivated by personal financial gain
  • B. A government-sponsored group with significant resources, advanced capabilities, and long-term strategic objectives, conducting espionage, sabotage, or influence operations on behalf of a country
  • C. A hacktivist group protesting corporate environmental practices
  • D. An organized crime syndicate conducting ransomware attacks for profit

Nation-state actors are government-affiliated groups with substantial resources, advanced persistent threat (APT) capabilities, and geopolitical objectives. They are among the most sophisticated and well-funded threat actors. This is the correct answer.

What term describes an attacker who uses pre-built tools and exploits created by others without understanding the underlying techniques?
  • A. Nation-state actor
  • B. Script kiddie (unskilled attacker), an individual who uses pre-written exploits, hacking tools, and scripts without the technical knowledge to develop their own, typically seeking notoriety or entertainment rather than strategic objectives
  • C. Hacktivist
  • D. Insider threat

Script kiddies (unskilled attackers) rely on others' tools without understanding them, they are opportunistic, cause real damage, but lack the sophistication to develop novel attacks. This is the correct answer.

A critical infrastructure company discovers attackers have been inside their network for 18 months, silently mapping SCADA systems without causing disruption. Which threat actor type does this behavior MOST likely indicate?
  • A. Unskilled attacker, they could not find the data they were looking for
  • B. Nation-state actor, the 18-month dwell time, focus on critical infrastructure mapping, and non-destructive patience are hallmarks of a nation-state advanced persistent threat (APT) pre-positioning for potential future disruption
  • C. Organized crime, they are preparing a ransomware deployment
  • D. Hacktivist, they are documenting the company's environmental violations

Long-term stealthy access to critical infrastructure with mapping but no immediate destruction is a nation-state APT signature, pre-positioning for potential future use in geopolitical conflict. This is the correct answer.

An unskilled attacker downloads a popular exploit kit and uses it to attack random internet-accessible servers. Despite low sophistication, why are unskilled attackers still a significant threat to organizations?
  • A. Unskilled attackers are not a significant threat, only sophisticated actors cause real damage
  • B. Unskilled attackers are significant because: exploit kits are highly capable (created by skilled developers); they attack at massive scale (opportunistic, automated scanning); they successfully compromise unpatched systems regardless of attacker sophistication; they may inadvertently cause significant damage; and their volume means any organization with common vulnerabilities will eventually be targeted
  • C. Unskilled attackers target only home users, not organizations
  • D. Unskilled attackers only pose reputational risk, they cannot cause operational damage

The democratization of attack tools means unskilled attackers wield sophisticated capabilities, volume and opportunistic targeting ensure that vulnerable organizations will be hit regardless of attacker skill. This is the correct answer.

A hacktivist group defaces a pharmaceutical company's website with messaging criticizing drug pricing and leaks internal emails discussing pricing strategies. Which combination of attack types did they use and what were their apparent objectives?
  • A. They used ransomware for financial gain
  • B. They used web defacement (to publicly broadcast their message) and data exfiltration with public leaking (to embarrass the company and provide evidence for their cause). Their objectives were publicity, reputational damage to the target, and advancing their cause, not financial gain. The combination is characteristic of hacktivist operations
  • C. They conducted a DDoS attack to disrupt operations for profit
  • D. They performed reconnaissance to sell the data to competitors

Hacktivist operations typically combine techniques to maximize publicity and embarrassment, defacement broadcasts the message, leaking provides supporting evidence, and both achieve reputational damage to advance their cause. This is the correct answer.

A nation-state conducts a supply chain attack, compromising a software vendor's build process to distribute malware to thousands of organizations simultaneously. Which aspects of this attack reflect nation-state capabilities specifically?
  • A. The use of malware, any threat actor can use malware
  • B. The combination of: sophisticated capability to compromise a well-secured software vendor; patience and resources to develop and maintain the operation over months; intelligence to select a high-value supply chain target affecting thousands of victims simultaneously; and strategic intent to access specific high-value targets among the thousands affected, these multi-dimensional requirements distinguish nation-state operations
  • C. The fact that many organizations were affected, scale alone indicates nation-state involvement
  • D. The use of a software vendor as the attack vector, only nation-states use supply chain attacks

Nation-state supply chain attacks require the combination of sophisticated vendor compromise capability, operational patience, intelligence-driven target selection, and strategic purpose beyond financial gain, these requirements together distinguish nation-state actors. This is the correct answer.

A security team discovers what appears to be a nation-state APT in their network. The attacker has not yet achieved their apparent objective. The team debates whether to immediately eject the attacker or monitor for intelligence value. What are the key considerations in this decision?
  • A. Always immediately eject all attackers, monitoring provides no benefit
  • B. Monitoring considerations: intelligence value (understanding objectives, TTPs, and targets helps defenders and intelligence agencies), risk of further damage during monitoring period, legal and notification obligations, and whether the attacker will detect monitoring and escalate. Ejection considerations: immediate risk reduction, compliance requirements, liability during monitoring, and the difficulty of ensuring complete eradication. Legal counsel and law enforcement should be consulted, the decision involves significant legal, ethical, and operational trade-offs
  • C. Always monitor indefinitely, intelligence gathering always outweighs risks
  • D. The decision belongs entirely to the IT security team without legal or executive involvement

Nation-state APT monitoring vs. ejection involves complex legal, operational, and strategic considerations requiring multi-stakeholder input. Both approaches have legitimate justifications depending on context. This is the correct answer.

A security analyst notices that identical exploitation attempts against their organization match public proof-of-concept code released 3 days ago for a newly disclosed vulnerability. The attack is unsuccessful because the patch was applied 24 hours ago. What does this scenario illustrate about unskilled attacker behavior?
  • A. The attack proves the attacker is a nation-state actor, they move very quickly after disclosure
  • B. Unskilled attackers rapidly weaponize public exploits shortly after disclosure, the short window between disclosure and attack attempts demonstrates that patch deployment speed is critical. Organizations that patch quickly (as this one did) successfully defend against this common threat pattern. The matching of public PoC code confirms the attacker used existing tools rather than developed novel capability
  • C. The patch was unnecessary, the attack failed for other reasons
  • D. Unskilled attackers never succeed because they only use public tools

Unskilled attackers using public PoC code immediately after disclosure is a well-documented pattern, the organization's quick patching was effective precisely because unskilled attackers rely on known exploits. This is the correct answer.

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/comptia-security-plus/threats-vulnerabilities-and-mitigations/

<a href="https://quizbuffet.com/comptia-security-plus/threats-vulnerabilities-and-mitigations/">CompTIA Security+ Threats, Vulnerabilities, and Mitigations practice quiz on QuizBuffet</a>

Other SY0-701 Domains

← Back to SY0-701 practice test overview

Questions are written against the published SY0-701 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.