CompTIA Security+ guideHigh-value skills

Security+ Threats and Vulnerabilities Study Guide

Threats, Vulnerabilities, and Mitigations is 22% of SY0-701. Practice the difference between the actor, the path, the weakness, and the fix.

Short answer

On SY0-701, Threats, Vulnerabilities, and Mitigations is 22% of the blueprint. The useful skill is a split: the actor is who, the vector is the path, the vulnerability is the weakness, the exploit is the use of that weakness, and the mitigation has to interrupt that path. A weight is not a guaranteed question count. These scenarios are original.

The domain is a matching problem

CompTIA assigns 22% of SY0-701 to Threats, Vulnerabilities, and Mitigations. That is the second-largest weight, after Security Operations at 28%. It is still not a quota of questions. The objectives ask you to compare actors and motivations, explain vectors, explain vulnerability types, analyze malicious activity, and choose mitigations such as segmentation, hardening, and patching.

A malware catalog is the wrong study shape. Two ransomware families can share a name and still be the wrong thing to memorize. What the item usually needs is the role of each noun in the sentence.

WordThe question it answersOriginal example
Threat actorWho is acting, and what do they want?A criminal group that sells access
Threat vectorHow does the attempt arrive?A fake payroll message
VulnerabilityWhat weakness makes the attempt possible?An unpatched VPN, or a person who will type a password into a copied site
ExploitWhat was done with that weakness?Code that uses the VPN flaw, or the fraudulent site itself
MitigationWhat change interrupts this story?Patch and restrict the VPN, or a process that does not trust the payroll link

The mitigation has to fit. Segmentation limits a compromised host that is scanning neighbors. It does not undo a leaked password by itself. A password manager does not close an exposed management port. Patching the VPN does not train people to recognize a payroll lure. Pick the sentence you were given. Naming the control’s category and function is the security controls guide. Choosing a scan versus a penetration test is a different job, in vulnerability scanning versus penetration testing.

Three original scenarios

Unpatched edge device. A VPN appliance on the internet is missing a fix that the vendor published last month. Nothing has been run against it yet. The vulnerability is the missing fix. There is no exploit in the story yet. The mitigation is to patch, or to remove the exposure if you cannot patch yet. Calling the vendor “the attacker” confuses a missing update with an actor.

Helpful insider. An employee copies a customer file to a personal storage account so they can work at home. The actor can be an insider without being a criminal group. The vector is an authorized person using an unsanctioned service. The mitigation might be a sanctioned transfer path and less standing access to the file, not a speech about nation-states.

Encrypted share. Files are being renamed by a process on one workstation, and that host can see the whole file server. You need two actions that are easy to mash together: contain the host, and restore from a backup the process could not reach. A longer screensaver setting does neither.

How to drill it

Write the five words next to a short paragraph from your own notes, not from a recalled exam item. If you cannot fill “mitigation” with something that changes the paragraph, you do not understand it yet.

Practice that split on an original Security+ item. The free set includes this kind of distinction. It is not a catalog of malware names, and it is not 22% of a real form.

Trust the source

Official sources

Exam policies can change. Use these primary sources for the most current details.