Exam objective

SY0-701 2.4: Malicious Activity Indicators

Security+ Topic

Malicious Activity Indicators for Security+

This Security+ topic covers observable clues that suggest malicious activity may be occurring or has occurred. It teaches how to analyze symptoms, telemetry, user reports, system behavior, access patterns, service behavior, and attack-specific clues.

Start first lesson

5 lessons in this topic

Common mistakes to avoid

1

Learners often confuse worms and viruses. A worm self-propagates across systems or networks. A virus attaches to a host file or program and spreads when that host runs.

2

Learners often choose the control that failed instead of the indicator. A badge reader, lock, camera, or sensor is a control. The indicator is the suspicious evidence: cloned badge behavior, forced-entry marks, abnormal environment, or tampering.

3

Learners often choose the mitigation instead of the indicator. Rate limiting, filtering, segmentation, secure DNS, VPNs, and monitoring are controls.

4

Learners often answer with the vulnerability class when the question asks for observed activity. That can be acceptable when the answer choices are attack indicators, but explanations should stay evidence-focused: suspicious input, crashes, repeated requests,...