SY0-701 · Domain 2 of 5 by weight

Threats, Vulnerabilities, and Mitigations

By · Updated 2026-07-13

Exam weight
22%
Approx. questions
~20
Topics
4

Threats, Vulnerabilities, and Mitigations accounts for 22% of the CompTIA Security+ — roughly 20 of the 90 questions you will see. It ranks 2 of 5 by weight, so it deserves proportionate — not equal — study time.

What this domain actually tests

The second-heaviest domain, and the most scenario-driven on the exam.

The exam's signature move is symptom-first. It does not ask "define smishing." It says: "An employee receives a text message appearing to come from the CEO, asking them to urgently purchase gift cards…" and asks what is happening.

That changes how you must study. If your notes are a list of definitions, you are preparing for a test this exam does not give. You need to go from indicator to attack name to mitigation, and you need to do it in the direction the exam asks.

The traps

Build the material as symptom → attack → mitigation triples:

Symptom in the stemAttackMitigation
Text message impersonating an executiveSmishingAwareness training, out-of-band verification
Phone call impersonating IT supportVishingAwareness training, callback procedures
Email targeting one senior executiveWhalingAwareness training, email filtering
Login form errors when input contains 'SQL injectionParameterised queries, input validation
Script runs in another user's browser sessionXSSOutput encoding, CSP
Action performed as a logged-in user without consentCSRFAnti-forgery tokens
Traffic silently intercepted and alteredOn-path (MITM)TLS, certificate pinning
Malware spreading with no user actionWormSegmentation, patching
Malware hiding itself at kernel levelRootkitSecure boot, integrity monitoring

Worm versus virus is the classic pair: a worm self-propagates across a network with no user interaction; a virus needs a user to run something. The phrase "with no user interaction" in a stem is the tell.

Vulnerability scan versus penetration test. A scan finds and reports weaknesses. A pen test actively exploits them to prove impact. If the requirement is to demonstrate what an attacker could actually achieve, it is a pen test — and it requires written authorisation, which is itself examinable.

Risk, threat, and vulnerability are three different words. A vulnerability is the weakness. A threat is what might exploit it. Risk is the likelihood and impact of that happening. The exam uses them precisely and swaps them to catch you.

How to study it

Study by symptom, not by definition. For each attack, write down what a user or a log would actually report — then work backwards to the name.

Then build the mitigation half, because the exam frequently asks it as a pair: it describes an attack and asks which control prevents it. Knowing that XSS exists is worth nothing if you cannot say "output encoding."

Give this domain two full weeks. It is 22% of the exam, everything downstream borrows its vocabulary, and it is the domain where the symptom-first framing punishes passive reading most severely.

What this domain covers

  • Malware types and attack vectors
  • Social engineering and phishing
  • Vulnerability scanning and penetration testing
  • Indicators of compromise

These are the topics Prepa uses to generate SY0-701 practice questions for this domain, so your practice is weighted the way the exam is.

The other SY0-701 domains

For the full exam format, scoring, and a study plan, read the CompTIA Security+ (SY0-701) Study Guide.

Related reading