Transit GIS staff open a "map update" image that later appears to have delivered a malicious payload through embedded content rather than a normal office document. At Security+ depth, which threat vector should analysts primarily consider?
Select an answer to reveal the explanation.
Short Explanation
When the "map update" picture is the delivery truck, think image-based vector — malware or hidden content riding an image, not just a Word macro. Security+ expects awareness that images can be a channel alongside email attachments. Scan and sandbox unusual GIS media the same way you would shady documents.
Full Explanation
Objective 2.2 includes image-based vectors so candidates recognize that threats are not limited to traditional executables and email bodies. Steganography or malicious image-borne content can deliver or conceal payloads. Open RDP defaults, pretexting, and public cloud buckets are different surfaces. Municipal GIS workflows should treat unsolicited map media as untrusted input subject to scanning and least privilege.