CompTIA Security+ (SY0-701)/Topics/Threats, Attacks & Vulnerabilities

Threats, Attacks & Vulnerabilities practice test: free CompTIA Security+ (SY0-701) questions

Drill 38 Threats, Attacks & Vulnerabilities questions with instant explanations and official citations.

Practice domain

Topic overview & passing targets

Threats, Attacks & Vulnerabilities Domain Overview

The Threats, Attacks & Vulnerabilities module is a core testing domain on the CompTIA Security+ (SY0-701). QuizCram provides 38 practice questions for this domain with verified handbook rationales.

  • Target Passing Benchmark: 83% (SY0-701 · maximum of 90 items · 90-minute limit · 750/900 to pass)
  • Domain Questions: 38 items
  • Source Material: Official Handbooks

Sample Practice Questions for Threats, Attacks & Vulnerabilities

  1. Question 1Ref: CompTIA Security+ SY0-701 — 1.1 Malware Types

    A user unknowingly installs a program that displays unwanted advertisements and tracks browsing habits to deliver targeted pop-ups. Which type of malware is this?

    Show Answer & Explanation

    Correct Answer
    A. Adware

    The keyed answer is "Adware". Adware automatically displays or downloads advertising material and may track browsing habits to deliver targeted ads. Fileless malware operates in memory, worms self-replicate across networks, and keyloggers record keystrokes to steal credentials.

  2. Question 2Ref: CompTIA Security+ SY0-701 — 1.1 Vulnerability Types

    A security researcher discovers a previously unknown vulnerability in a widely used operating system before the vendor has released a patch. What type of vulnerability is this?

    Show Answer & Explanation

    Correct Answer
    D. Zero-day vulnerability

    The keyed answer is "Zero-day vulnerability". A zero-day vulnerability is a previously unknown flaw discovered before the vendor releases a fix, giving attackers an opportunity to exploit it. Legacy vulnerabilities are old and known, configuration weaknesses are setup errors, and design flaws are architectural issues.

  3. Question 3Ref: CompTIA Security+ SY0-701 — 1.4 Application Attacks

    An attacker exploits a web application by inserting malicious SQL commands into a search field to extract database contents. What type of vulnerability is being exploited?

    Show Answer & Explanation

    Correct Answer
    C. SQL injection

    The keyed answer is "SQL injection". SQL injection occurs when an attacker inserts malicious SQL commands into input fields, manipulating database queries to extract or modify data. XSS injects client-side scripts, SSRF makes requests from the server, and IDOR accesses unauthorized resources.

  4. Question 4Ref: CompTIA Security+ SY0-701 — 1.3 Identity-Based Attacks

    An attacker uses a list of username and password pairs obtained from a previous data breach to attempt access to a company's cloud services. Which type of attack is this?

    Show Answer & Explanation

    Correct Answer
    A. Credential stuffing

    The keyed answer is "Credential stuffing". Credential stuffing uses username and password pairs stolen from one breach to attempt access on other systems, exploiting password reuse. Privilege escalation elevates permissions, session hijacking steals active sessions, and pass-the-hash uses captured password hashes.

  5. Question 5Ref: CompTIA Security+ SY0-701 — 1.2 Threat Actors and Attack Vectors

    A security analyst discovers a phishing email targeting employees with a link to a credential-harvesting site. Which technical control would BEST prevent users from accessing this site?

    Show Answer & Explanation

    Correct Answer
    B. Implement a web content filter with known malicious URL categories

    A web content filter that blocks known malicious URLs is the most direct technical control for preventing access to credential-harvesting sites. While MFA, training, and sandboxing are valuable, they do not directly block access to a specific malicious URL at the network level.

Frequently Asked Questions About Threats, Attacks & Vulnerabilities

QuizCram covers 38 practice questions in the Threats, Attacks & Vulnerabilities domain, mapped directly to the official examination blueprint.

The benchmark score is 83% (SY0-701 · maximum of 90 items · 90-minute limit · 750/900 to pass).

Yes. All questions on QuizCram are written against official handbooks and blueprint specifications with legal citations.