A+ Lesson

Classifying Attacks, Threats, and Vulnerabilities for A+

Last updated: 6/10/2026

Short answer

Classification is a decision tree: 1) Is the primary vector human interaction or manipulation? If yes, social engineering. 2) Is the primary observable evidence network/service anomalies, repeated authentication failures, or exploit behavior? If yes, technical threat. 3) Is the primary observation a state or configuration lacking protections (unpatched, EOL, no antivirus)? If yes, vulnerability condition. Use the most immediate observable factor to assign category; multiple categories can apply, but classification should reflect primary triage action.

Why it appears on the exam

- Given a multi-faceted scenario, identify the correct primary classification and list the secondary items to document. - Choose the correct next-step action for each classification (e.g., verify identity for social engineering, collect logs for technical threat, flag asset for patching for vulnerability).

Key concepts

Concept 1

Required terms

classification categories: The three primary categories used in this topic: social engineering (human-targeted deception), technical threats (active attacks against systems or networks), and vulnerability conditions (existing weaknesses that increase risk).

Example

User clicked a link in an email that requested credentials -> social engineering (phishing).

Concept 2

How Classifying Attacks, Threats, and Vulnerabilities works

Classification is a decision tree: 1) Is the primary vector human interaction or manipulation? If yes, social engineering. 2) Is the primary observable evidence network/service anomalies, repeated authentication failures, or exploit behavior? If yes, technical threat. 3) Is the primary observation a state or configuration lacking protections (unpatched, EOL, no antivirus)? If yes, vulnerability condition. Use the most immediate observable factor to assign category; multiple categories can apply, but classification should reflect primary triage action.

Example

Multiple failed logins for an account observed in logs -> technical threat (brute-force).

Concept 3

Common confusion

Students frequently conflate cause and effect: an attacker may exploit a vulnerability via phishing, but the initial report might be a phishing email. Teach to classify by the primary symptom the user reports and then document linked vulnerabilities as part of the incident record.

Example

A server missing vendor updates identified in asset inventory -> vulnerability condition (unpatched/EOL).

Concept 4

Core 2 (220-1202) question cues

Given a multi-faceted scenario, identify the correct primary classification and list the secondary items to document; Choose the correct next-step action for each classification (e.g., verify identity for social engineering, collect logs for technical threat, flag asset for patching for vulnerability).

Example

Scenario with an email spoofing the CFO and a misplaced unpatched server: classify the immediate report per primary evidence (email content -> social engineering) and flag the server as separate vulnerability.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.In an A+ question, this detail appears: User clicked a link in an email that requested credentials -> social engineering (phishing). Which option matches it?

Q2.For this A+ objective, the scenario says: Multiple failed logins for an account observed in logs -> technical threat (brute-force). What is the best match?

Q3.A support scenario about Classifying Attacks, Threats, and Vulnerabilities feels similar to a nearby topic. What is the safest way to choose an answer?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8