Exam objective
Core 2 2.0: Social Engineering, Threats, and Vulnerabilities
Social Engineering, Threats, and Vulnerabilities for A+
This A+ topic provides CompTIA A+ Core 2 technician-level recognition and classification guidance for social engineering attacks, common threat categories, and vulnerability conditions. The focus is identification and correct categorization from practical support scenarios. This topic explicitly excludes deep malware analysis, step-by-step incident remediation, developer-level web security, and network hardening procedures.
Start first lesson6 lessons in this topic
Common mistakes to avoid
People often treat any unsolicited security prompt as legitimate, especially if it imitates familiar language. Another confusion is equating spear phishing with generic phishing; the difference is personalization and intent.
Technicians sometimes mistake legitimate traffic surges for DDoS, or confuse evil twin SSIDs with legitimate roaming networks. Distinguish by checking IP distributions, request patterns, and comparing BSSIDs/MACs or certificate chains.
Learners often conflate caller ID spoofing with insider compromise; they are different: spoofing falsifies identifiers externally, insider risk is about authorized users misusing access.
Learners sometimes treat SQL injection and XSS interchangeably; the key difference is target: server-side database vs. client-side script execution. Zero-day is often confused with unpatched known vulnerabilities; zero-day has no vendor fix at discovery.