Exam objective
SY0-701 2.2: Threat Vectors and Attack Surfaces
Threat Vectors and Attack Surfaces for Security+
This Security+ topic covers recognition of the path, channel, or exposed entry point an attacker could use. It teaches delivery vectors and exposure surfaces, not the later evidence that an attack succeeded; Local ownership:; securityplus.tvm.vectors.messaging1: message and media paths, including email, Short Message Service (SMS), instant messaging (IM), image-based delivery, file-based delivery, voice call delivery, and removable device delivery; securityplus.tvm.vectors.software2: software and system exposure, including vulnerable software, client-based versus agentless exposure, unsupported systems and applic...
Start first lesson5 lessons in this topic
Common mistakes to avoid
Learners often mix the delivery path with the attack result. If the question asks how the attacker reached the target, answer with the vector such as email, SMS, IM, file, image, voice call, or removable device.
Open ports, vulnerable software, and default credentials are exposure clues, not automatic indicators of attack. If the prompt asks what made the system reachable, stay in attack surface.
Learners often confuse network vector with mitigation. The question here asks which network path creates exposure. Secure wireless configuration, network access control, segmentation, and monitoring are mitigation topics elsewhere.
Supply chain is not the same as third-party risk management. This section asks whether a third party is the path into the organization.