Exam objective
SY0-701 2.4: Malicious Activity Indicators
Malicious Activity Indicators for Security+
This Security+ topic covers observable clues that suggest malicious activity may be occurring or has occurred. It teaches how to analyze symptoms, telemetry, user reports, system behavior, access patterns, service behavior, and attack-specific clues.
Start first lesson5 lessons in this topic
Common mistakes to avoid
Learners often confuse worms and viruses. A worm self-propagates across systems or networks. A virus attaches to a host file or program and spreads when that host runs.
Learners often choose the control that failed instead of the indicator. A badge reader, lock, camera, or sensor is a control. The indicator is the suspicious evidence: cloned badge behavior, forced-entry marks, abnormal environment, or tampering.
Learners often choose the mitigation instead of the indicator. Rate limiting, filtering, segmentation, secure DNS, VPNs, and monitoring are controls.
Learners often answer with the vulnerability class when the question asks for observed activity. That can be acceptable when the answer choices are attack indicators, but explanations should stay evidence-focused: suspicious input, crashes, repeated requests,...