CompTIA Security+ SY0-701 · Free study guide
Objective 2.2 — Recognize common attack paths and exposed surfaces
A threat vector is the path used to reach a target; an attack surface is the set of reachable opportunities. Defenders reduce risk by mapping both. A phishing email is a vector, while mailboxes, browsers, identity workflows, and users form parts of the surface it can exploit.
Message-based attacks can arrive through email, SMS, or instant messaging. Images may hide misleading codes or links, and files may contain active content or weaponized formats. Voice calls support vishing and help an attacker apply pressure. Removable media can cross network boundaries and trigger malicious code or data loss. Controls should cover content, identity, behavior, and reporting rather than assuming one gateway sees every channel.
Technical exposure
Open service ports are not automatically vulnerabilities, but each reachable service needs a business owner, secure configuration, authentication, patching, and monitoring. Default credentials turn normal access paths into trivial compromise. Unsupported software increases exposure because newly discovered flaws may receive no fix. Agent-based products install local code and can see device activity; agentless products often rely on network or management interfaces. Their blind spots differ.
Unsecure wired, wireless, and Bluetooth connections can expose traffic or device control. Segment untrusted clients, use modern authentication and encryption, disable unused radios and services, and monitor for unauthorized infrastructure.
Supply chain and people
Managed service providers, software vendors, hardware suppliers, and other partners can become indirect paths. A trusted update channel can distribute malicious code; an overprivileged support account can cross customer boundaries. Due diligence, scoped access, signed updates, monitoring, and incident obligations reduce but do not eliminate the risk.
Social-engineering forms differ by delivery and story. Phishing uses deceptive messages; smishing uses SMS; vishing uses voice. Pretexting builds a convincing scenario. Business email compromise impersonates or controls a trusted business identity, often to alter payments. Typosquatting and brand impersonation create look-alike destinations. A watering-hole attack compromises a site the intended targets already visit. Misinformation and disinformation can create confusion that supports another attack.
When reviewing a scenario, trace the full chain: entry channel, human or technical decision, credential or code execution, lateral path, and target. The strongest mitigation often interrupts several points—for example, verified payment-change procedures plus MFA, domain protections, and anomaly detection.
Decision rule: name the path actually shown by evidence, then reduce both the immediate vector and the broader exposed surface.
Practice and apply this objective
A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.
Start practicing free