Threats, Vulnerabilities, and Mitigations
SY0-701 · 66 questions
- Sophisticated probes against the dam SCADA vendor portal appear aimed at long-term intelligence collection and show high funding and custom tooling. Which threat-actor profile best fits?
- Overnight logs show repeated default-password attempts against the public library Wi-Fi admin page using widely published tools. Which actor attribute set is most accurate?
- After a contentious city council vote, attackers deface the mayor's public website with political slogans but make no ransom demand. Which motivation and actor type best describe the activity?
- A public-works employee with legitimate GIS access copies sensitive infrastructure layers to personal media shortly before resigning. Which threat category does this primarily illustrate?
- Attackers encrypt the county permit system and demand payment to restore operations. Which threat-actor motivation pairing is most consistent with this pattern?
- A parks department quietly adopts an unsanctioned public SaaS form tool for event registrations without IT review. How should security classify this situation?
- Analysts compare two campaigns against the municipal utility: one is external with high funding and advanced tooling; the other is internal with limited skill. Which attribute pairing best describes the well-resourced external campaign?
- Intruders quietly steal voter-roll exports from a county system and prepare them for sale, without knocking services offline. Which motivation best matches this behavior?
- After sensitive HR files are stolen from a city shared drive, attackers threaten to publish them unless officials meet demands. Which motivation framing is most accurate?
- A former contractor, angry after a contract non-renewal, targets the city's ticketing system to cause damage. Which motivation best classifies this activity?
- Destructive malware hits municipal water-treatment controls in the same week as escalating geopolitical conflict, with no ransom note. Which motivation category is most consistent?
- An outside researcher accesses a city system without permission, then claims an 'ethical' motive after publicly posting findings. How should the city treat that access?
- A finance clerk receives an unexpected email urging an immediate change to vendor wire instructions. Which threat vector best describes this attack?
- City employees receive text messages pretending to be the municipal MFA reset help line and asking for one-time codes. Which attack type is this?
- A city help desk receives a phone call from someone claiming to be the CIO who urgently demands a password reset for a privileged account and refuses to use the ticket portal. Which threat vector best describes this attempt?
- Accounts payable at the county construction office receives an email from what looks like a long-time vendor asking to redirect the next progress payment to a new bank account. The From domain is one character off the real vendor domain. Which attack best matches this scenario?
- Security finds several unlabeled USB drives left in the visitor parking lot outside city hall, some labeled "Q4 budget draft." An employee plugs one into a clerk workstation and malware begins beaconing. Which threat vector is primarily illustrated?
- The DMV still runs public-facing Windows 7 kiosks that are joined to the staff network and no longer receive vendor security updates. Which attack-surface concern does this primarily represent?
- A scanner finds a public-facing municipal jump host with Remote Desktop exposed to the Internet and the vendor default administrator password still in use. Which combination of vectors does this primarily illustrate?
- Attackers breach the remote-support platform used by the city’s managed service provider and then reach multiple municipal endpoints through that trusted tooling. Which attack surface best describes this event?
- Threat intelligence reports that attackers compromised a niche municipal-procurement discussion forum that purchasing staff visit weekly, then served malware to visitors. Which threat vector is this?
- A caller tells the facilities clerk they are conducting an unannounced physical-security audit for the county and need today’s badge door codes "for the checklist." Which social-engineering technique is primarily in play?
- False boil-water alerts flood the city’s social channels, creating public panic while attackers simultaneously phish residents toward fake "emergency portal" login pages. Which threat vector is primarily illustrated by the false alerts?
- A library guest Wi-Fi SSID is bridged into the same VLAN as staff workstations with no client isolation, allowing a visitor laptop to reach clerk file shares. Which threat vector best describes this condition?
- Transit GIS staff open a "map update" image that later appears to have delivered a malicious payload through embedded content rather than a normal office document. At Security+ depth, which threat vector should analysts primarily consider?
- Clerk workstations still run an unpatched browser plugin that agentless network scans never inventory, and several drive-by attempts target that plugin. Which attack-surface issue is most directly highlighted?
- A building-permit web application concatenates citizen form fields directly into SQL statements, and testers can alter queries to return other applicants’ records. Which vulnerability type is this?
- A citizen-comment portal reflects unsanitized input into pages other residents view, and a crafted script steals session cookies from those browsers. Which vulnerability is demonstrated?
- A legacy document-scanning service crashes when fed an oversized input, and analysis shows adjacent memory was overwritten before a suspicious process started. Which application vulnerability class best fits?
- On a shared municipal app server, a process checks a file’s permissions, then an attacker replaces the file before it is used, gaining unauthorized access. Which vulnerability does this describe?
- Building-badge door controllers still run firmware last updated years ago, and the vendor has published critical fixes the city never applied. Which vulnerability class is primarily involved?
- The city’s edge firewall has reached vendor end-of-life and will receive no further security patches, yet it still terminates Internet traffic for several departments. Which vulnerability concern is most accurate?
- A single hypervisor hosts both a low-trust guest Wi-Fi captive portal VM and finance application VMs with weak isolation controls. Leadership asks what vulnerability would let an attacker break out of the portal guest. Which concept applies?
- A county open-data project discovers a cloud storage bucket holding draft resident datasets is configured for public read without authentication. Which vulnerability type best describes this finding?
- A trusted software vendor’s update channel is compromised and a malicious build is pushed to municipal workstations that auto-install the update. Which vulnerability / attack theme does this primarily represent?
- Inspectors jailbreak city-issued tablets and sideload unapproved field apps, bypassing MDM restrictions that blocked those installs. Which mobile vulnerability theme is most accurate?
- Researchers disclose a critical flaw in the VPN appliance the city uses, but the vendor has not released a patch yet and active exploitation is reported elsewhere. Which vulnerability class best fits?
- A parking-payment kiosk still allows a weak legacy TLS cipher suite that security scanners flag as outdated and breakable with known attacks. Which vulnerability type is primarily indicated?
- Domain-joined clerk PCs remain missing a published OS security update that enables local privilege escalation, and attackers who phish one user become local admins. Which vulnerability class best describes the missing fix?
- County clerk workstations suddenly show ransom notes on the desktop and many files have unfamiliar encrypted extensions. Which malware indicator best matches this activity?
- A public-works technician installs a 'helpful' remote-support utility that arrived in email. Investigators later find a hidden backdoor. Which malware classification best fits the original installer?
- Malware on the city network is hopping from host to host across a VLAN without clerks clicking attachments. How does this behavior primarily differ from a classic file-infecting virus?
- Before an ACH batch leaves finance, malware on a clerk PC quietly records every keystroke. Which malware class best describes this behavior?
- A contractor's access ends Friday, and Saturday morning a script on a records server deletes selected case files. Which malware pattern does this most clearly illustrate?
- On a municipal jump server, local antivirus shows a clean bill of health, yet an offline integrity tool reveals hidden processes and altered system binaries. Which malware category best explains the concealment?
- Security cameras show a stranger lingering at the city garage badge reader with a handheld device, and the next morning an unused cloned badge opens the door. Which attack indicator is this?
- The city's public website is unreachable while edge logs show huge inbound UDP replies from many third-party resolvers after small spoofed queries. Which network attack pattern best matches these indicators?
- Payroll staff report the familiar portal URL opening a lookalike login page. Recursive resolver cache shows unexpected A records for the official hostname. Which malicious activity indicator fits best?
- On city hall guest Wi-Fi, several browsers suddenly warn about unexpected certificates and session contents appear altered mid-transfer. Which attack indicator does this describe?
- Identity logs show many municipal accounts receiving one or two failed logons with the same common password, then quiet periods, rather than thousands of guesses against one account. Which attack pattern is this?
- A legacy utility appliance renegotiates its management session to outdated weak ciphers after an attacker interferes with the handshake. Which cryptographic attack is occurring?
- An analyst sees a successful city VPN login from headquarters, then another success from overseas minutes later for the same user. Which identity anomaly indicator should be treated as suspicious?
- After a suspected intrusion on a critical permits server, investigators find large gaps where security and authentication logs should exist. What malicious indicator does this most strongly suggest?
- Web logs for the municipal document portal show requests with sequences like ../ and paths resembling /etc/passwd under the application URL. Which application attack indicator is this?
- After a phishing wave hits enterprise IT, leadership wants to reduce the chance that malware can reach water-plant SCADA. Which mitigation best limits that blast radius?
- Too many departments can write to the city finance file share after a permissions creep review. Which mitigation best reduces unauthorized access?
- Election clerk workstations must run only a small set of approved voting-support programs. Which mitigation enforces that control?
- A critical CVE on the city's VPN concentrator now has public exploit code circulating. Which mitigation should be prioritized first for that vulnerability?
- Lobby information kiosks need stronger endpoint hardening beyond signature AV alone. Which pair of controls best matches common host-hardening mitigations?
- New access-layer switches arrive with default credentials and many unused services enabled. Which baseline hardening steps should operations apply before production use?
- A CAD workstation used for public-works drawings is confirmed malware-infected. Which mitigation contains the host while still supporting investigation?
- Sensitive backup tapes must leave the records center for off-site storage. Which mitigation best protects confidentiality if a courier loses a case?
- Hardened workstation images disable RDP, but weeks later drift re-enables it on several clerk PCs. Which mitigation keeps the secure baseline from eroding?
- Retired municipal file servers still sit online with old shares after their replacements go live. Which mitigation best reduces lingering exposure?
- A county launches a new public permitting portal and wants to catch misuse quickly after go-live. Which mitigation pairs best with the new exposure?
- A vendor appliance in the municipal data center has a critical patch, but a change freeze blocks immediate installation. Which interim mitigation best reduces exposure until the patch window opens?