2.2 Explain common threat vectors and attack surfaces
Domain 2: Threats, Vulnerabilities, and Mitigations
Threat vectors and attack surfaces cover how attacks arrive: message-based vectors (email, SMS, instant messaging), images, files, voice calls, removable devices, vulnerable software, unsupported systems, unsecure networks (wireless, wired, Bluetooth), open service ports, default credentials, and supply chain (managed service providers, vendors, suppliers). Social engineering carries the most weight here — phishing, vishing, smishing, misinformation and disinformation, impersonation, business email compromise, pretexting, watering hole attacks, brand impersonation, and typosquatting. The exam loves fine distinctions: smishing uses SMS, vishing uses voice, BEC impersonates an executive or trusted partner to move money, and a watering hole compromises a site the target already visits. Expect scenario questions where the delivery detail decides the answer. Also understand supply chain exposure conceptually: you inherit the risk of every vendor and MSP you trust. Candidates who only study phishing generically miss the variant-level questions this objective actually asks.
What you must know
- Phishing variants
- Business email compromise
- Watering hole attacks
- Supply chain vectors
- Typosquatting
- Default credentials
common pitfall · Candidates blur the social engineering variants — the channel (SMS, voice, email) and the impersonated party are exactly what the question is testing.
Try sample questions
A security manager is prioritizing controls against message-based threat vectors after several employees were tricked into revealing credentials. Which TWO of the following attack techniques arrive through message-based vectors? (Select TWO.)
- A Phishing emails containing credential-harvesting links
- B BlueBorne-style Bluetooth exploitation of nearby devices
- C Smishing texts impersonating a package courier
- D Malicious USB cables left in common areas
- E Exploitation of default credentials on network devices
Show answer & explanations
- A correct ·Correct. Email is a core message-based threat vector; phishing messages deliver credential-harvesting links directly to users' inboxes, making this one of the most common initial access techniques.
- B Bluetooth attacks travel over a short-range wireless vector, exploiting the radio interface of nearby devices rather than any messaging channel that delivers deceptive content to a user.
- C correct ·Correct. SMS text messaging is a message-based vector; smishing uses fraudulent texts, such as fake delivery notices, to lure victims into revealing credentials or installing malware.
- D Malicious cables and drives belong to the removable media and physical threat vectors; compromise occurs when the hardware is connected, not when a user reads a deceptive message.
- E Default credentials represent a weak-configuration attack surface on the devices themselves; exploiting them involves logging in directly and delivers no message of any kind to a user.
sample item — the full bank runs 450+ questions at exam difficulty
Several employees report finding branded USB flash drives scattered near the entrance of their office building. One employee plugs a drive into a corporate laptop, and malware immediately attempts to install. Which threat vector does this scenario demonstrate?
- A Removable media
- B Watering hole attack
- C Business email compromise
- D Typosquatting
Show answer & explanations
- A correct ·Correct. Baiting employees with infected USB drives exploits the removable media threat vector; the malware executes once curiosity leads someone to connect the untrusted device to a corporate system.
- B A watering hole attack compromises a legitimate website that the target group is known to visit frequently; it does not involve physically distributed storage devices left for victims to find.
- C Business email compromise uses spoofed or hijacked email accounts to trick staff into fraudulent payments or data disclosure; no email message plays any role in this scenario.
- D Typosquatting registers domain names that closely resemble legitimate ones to capture users who mistype URLs; this scenario involves physical devices rather than deceptive web addresses.
Is objective 2.2 your weak spot?
The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.
Check my readiness — free