Topic 06 Practice Test 1 covers Threat Vectors and Attack Surfaces for CompTIA Security+ SY0-701 and maps to objective 2.2: Explain common threat vectors and attack surfaces. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
To reach a target indirectly by abusing trusted third parties or dependencies, which security approach should be selected?
- Vishing
- Supply-chain vector
- Instant-messaging vector
- Impersonation
Correct Answer: B
Correct Answer
Answer B is correct because Supply-chain vector means compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source. This is the precise fit for the scenario. Vishing serves the different purpose of voice-based phishing performed through phone calls or other voice channels.
Incorrect Answers
Answer A is incorrect because Vishing refers to voice-based phishing performed through phone calls or other voice channels. The scenario instead requires compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source, which is why Supply-chain vector is the better answer; this option serves the different function defined above.
Answer C is incorrect because Instant-messaging vector refers to use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts. That concept can be valid in another scenario, but this question is testing compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source; Supply-chain vector therefore fits the requirement more directly.
Answer D is incorrect because Impersonation refers to pretending to be a trusted person, organization, or system. The concept is valid, but it does not match this stem. The required function is compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source, which maps to Supply-chain vector.
Question 2
A review during an attack-surface and threat-vector review identifies two gaps. One requires reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. The other requires pretending to be a trusted person, organization, or system. Which TWO options should be included in the remediation plan? Choose TWO.
- Unsecured wireless network
- Phishing
- Open service port
- Impersonation
- Default credentials
Correct Answers: C, D
Correct Answers
Answer C is correct because Open service port means a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. This selection maps directly to one of the named needs. Default credentials addresses vendor-supplied or predictable usernames and passwords that have not been changed, so it does not satisfy the same slot.
Answer D is correct because Impersonation means pretending to be a trusted person, organization, or system. It belongs in the fixed-count answer set because it covers one of the stated requirements. Default credentials instead serves vendor-supplied or predictable usernames and passwords that have not been changed and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Unsecured wireless network means a wireless environment with weak or absent security controls. Every answer slot must map to a stated requirement. The correct set is Open service port, Impersonation, so this option cannot replace one of those selections.
Answer B is incorrect because Phishing means a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action. The question requires exactly 2 selections: Open service port, Impersonation. This option falls outside that required set.
Answer E is incorrect because Default credentials means vendor-supplied or predictable usernames and passwords that have not been changed. The question requires exactly 2 selections: Open service port, Impersonation. This option falls outside that required set. For example, Open service port is required for a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.
Question 3
To exploit trust and urgency through telephone or voice communication, which security approach should be selected?
- Voice-call vector
- Unsecured wireless network
- Disinformation
- Smishing
Correct Answer: A
Correct Answer
Answer A is correct because Voice-call vector means use of spoken interaction to deceive a person into revealing information or taking an unsafe action. The requirement maps directly to this function, whereas Smishing is aimed at phishing delivered through SMS or text messaging.
Incorrect Answers
Answer B is incorrect because Unsecured wireless network refers to a wireless environment with weak or absent security controls. This could be appropriate elsewhere, but the required function is use of spoken interaction to deceive a person into revealing information or taking an unsafe action; that makes Voice-call vector the precise choice.
Answer C is incorrect because Disinformation refers to false information deliberately created or spread to deceive. That concept can be valid in another scenario, but this question is testing use of spoken interaction to deceive a person into revealing information or taking an unsafe action; Voice-call vector therefore fits the requirement more directly.
Answer D is incorrect because Smishing refers to phishing delivered through SMS or text messaging. The question is not asking for this function. It is testing use of spoken interaction to deceive a person into revealing information or taking an unsafe action, so Voice-call vector is the stronger fit.
Question 4
To intercept traffic, gain unauthorized connectivity, or stage local attacks, which security approach should be selected?
- Typosquatting
- SMS-based vector
- Vulnerable software
- Unsecured wireless network
Correct Answer: D
Correct Answer
Answer D is correct because Unsecured wireless network means a wireless environment with weak or absent security controls. This is the precise fit for the scenario. SMS-based vector serves the different purpose of delivery of malicious links or deceptive requests through text messaging.
Incorrect Answers
Answer A is incorrect because Typosquatting refers to registration or use of look-alike domain names based on common spelling mistakes. That concept can be valid in another scenario, but this question is testing a wireless environment with weak or absent security controls; Unsecured wireless network therefore fits the requirement more directly.
Answer B is incorrect because SMS-based vector refers to delivery of malicious links or deceptive requests through text messaging. The scenario instead requires a wireless environment with weak or absent security controls, which is why Unsecured wireless network is the better answer; this option serves the different function defined above.
Answer C is incorrect because Vulnerable software refers to software with an exploitable flaw that creates an attack surface. The concept is valid, but it does not match this stem. The required function is a wireless environment with weak or absent security controls, which maps to Unsecured wireless network.
Question 5
Which term describes false information deliberately created or spread to deceive?
- Pretexting
- Brand impersonation
- Email-based vector
- Disinformation
Correct Answer: D
Correct Answer
Answer D is correct because Disinformation means false information deliberately created or spread to deceive. That makes it the best answer here; Brand impersonation addresses use of a trusted company’s name, visual identity, or domain-like presence to deceive users, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Pretexting refers to social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request. The concept is valid, but it does not match this stem. The required function is false information deliberately created or spread to deceive, which maps to Disinformation.
Answer B is incorrect because Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users. The question is not asking for this function. It is testing false information deliberately created or spread to deceive, so Disinformation is the stronger fit.
Answer C is incorrect because Email-based vector refers to delivery of malicious links, attachments, requests, or social-engineering content through email. The question is not asking for this function. It is testing false information deliberately created or spread to deceive, so Disinformation is the stronger fit.
Question 6
To create confusion even when the distributor may believe the content is true, which security approach should be selected?
- Watering-hole attack
- SMS-based vector
- Voice-call vector
- Misinformation
Correct Answer: D
Correct Answer
Answer D is correct because Misinformation means false information that is shared without necessarily intending to deceive. This is the precise fit for the scenario. SMS-based vector serves the different purpose of delivery of malicious links or deceptive requests through text messaging.
Incorrect Answers
Answer A is incorrect because Watering-hole attack refers to compromise of a site or resource that the intended victims are known to visit. The concept is valid, but it does not match this stem. The required function is false information that is shared without necessarily intending to deceive, which maps to Misinformation.
Answer B is incorrect because SMS-based vector refers to delivery of malicious links or deceptive requests through text messaging. That concept can be valid in another scenario, but this question is testing false information that is shared without necessarily intending to deceive; Misinformation therefore fits the requirement more directly.
Answer C is incorrect because Voice-call vector refers to use of spoken interaction to deceive a person into revealing information or taking an unsafe action. That concept can be valid in another scenario, but this question is testing false information that is shared without necessarily intending to deceive; Misinformation therefore fits the requirement more directly.
Question 7
The control set for an attack-surface and threat-vector review must address both delivery of malicious links or deceptive requests through text messaging and use of USB or other removable media to introduce malware or move data. Which TWO choices map directly to those needs? Choose TWO.
- Unsecured wireless network
- Impersonation
- Voice-call vector
- SMS-based vector
- Removable-device vector
Correct Answers: D, E
Correct Answers
Answer D is correct because SMS-based vector means delivery of malicious links or deceptive requests through text messaging. It belongs in the fixed-count answer set because it covers one of the stated requirements. Unsecured wireless network instead serves a wireless environment with weak or absent security controls and cannot replace this function.
Answer E is correct because Removable-device vector means use of USB or other removable media to introduce malware or move data. This option satisfies a specific requirement in the stem; Impersonation serves pretending to be a trusted person, organization, or system and therefore is not interchangeable with it.
Incorrect Answers
Answer A is incorrect because Unsecured wireless network means a wireless environment with weak or absent security controls. Every answer slot must map to a stated requirement. The correct set is SMS-based vector, Removable-device vector, so this option cannot replace one of those selections.
Answer B is incorrect because Impersonation means pretending to be a trusted person, organization, or system. Every answer slot must map to a stated requirement. The correct set is SMS-based vector, Removable-device vector, so this option cannot replace one of those selections.
Answer C is incorrect because Voice-call vector means use of spoken interaction to deceive a person into revealing information or taking an unsafe action. The fixed-count answer set is SMS-based vector, Removable-device vector; this option does not fill one of those named functions.
Question 8
Which term describes delivery of malicious links or deceptive requests through text messaging?
- SMS-based vector
- Default credentials
- Business email compromise
- Typosquatting
Correct Answer: A
Correct Answer
Answer A is correct because SMS-based vector means delivery of malicious links or deceptive requests through text messaging. The deciding point is functional fit: this option covers the stated need, while Business email compromise addresses fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions.
Incorrect Answers
Answer B is incorrect because Default credentials refers to vendor-supplied or predictable usernames and passwords that have not been changed. This could be appropriate elsewhere, but the required function is delivery of malicious links or deceptive requests through text messaging; that makes SMS-based vector the precise choice.
Answer C is incorrect because Business email compromise refers to fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions. This could be appropriate elsewhere, but the required function is delivery of malicious links or deceptive requests through text messaging; that makes SMS-based vector the precise choice.
Answer D is incorrect because Typosquatting refers to registration or use of look-alike domain names based on common spelling mistakes. The scenario instead requires delivery of malicious links or deceptive requests through text messaging, which is why SMS-based vector is the better answer; this option serves the different function defined above.
Question 9
An architect working on an attack-surface and threat-vector review needs one capability that provides delivery of malicious links or deceptive requests through text messaging and another that provides deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action. Which TWO selections are the best match? Choose TWO.
- SMS-based vector
- Open service port
- Phishing
- Instant-messaging vector
- File-based vector
Correct Answers: A, C
Correct Answers
Answer A is correct because SMS-based vector means delivery of malicious links or deceptive requests through text messaging. One required function is exactly what this option provides. Instant-messaging vector may be useful elsewhere, but it is used for use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts.
Answer C is correct because Phishing means a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action. This selection maps directly to one of the named needs. File-based vector addresses use of a malicious or weaponized file as the initial delivery mechanism, so it does not satisfy the same slot.
Incorrect Answers
Answer B is incorrect because Open service port means a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. Every answer slot must map to a stated requirement. The correct set is SMS-based vector, Phishing, so this option cannot replace one of those selections.
Answer D is incorrect because Instant-messaging vector means use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts. The question requires exactly 2 selections: SMS-based vector, Phishing. This option falls outside that required set. For example, SMS-based vector is required for delivery of malicious links or deceptive requests through text messaging.
Answer E is incorrect because File-based vector means use of a malicious or weaponized file as the initial delivery mechanism. Every answer slot must map to a stated requirement. The correct set is SMS-based vector, Phishing, so this option cannot replace one of those selections.
Question 10
Which term describes software with an exploitable flaw that creates an attack surface?
- Business email compromise
- Disinformation
- Voice-call vector
- Vulnerable software
Correct Answer: D
Correct Answer
Answer D is correct because Vulnerable software means software with an exploitable flaw that creates an attack surface. The deciding point is functional fit: this option covers the stated need, while Disinformation addresses false information deliberately created or spread to deceive.
Incorrect Answers
Answer A is incorrect because Business email compromise refers to fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions. That concept can be valid in another scenario, but this question is testing software with an exploitable flaw that creates an attack surface; Vulnerable software therefore fits the requirement more directly.
Answer B is incorrect because Disinformation refers to false information deliberately created or spread to deceive. This could be appropriate elsewhere, but the required function is software with an exploitable flaw that creates an attack surface; that makes Vulnerable software the precise choice.
Answer C is incorrect because Voice-call vector refers to use of spoken interaction to deceive a person into revealing information or taking an unsafe action. The question is not asking for this function. It is testing software with an exploitable flaw that creates an attack surface, so Vulnerable software is the stronger fit.
Question 11
To exploit real-time enterprise messaging channels, which security approach should be selected?
- Instant-messaging vector
- Removable-device vector
- Watering-hole attack
- Smishing
Correct Answer: A
Correct Answer
Answer A is correct because Instant-messaging vector means use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts. That is the function the question is testing. Smishing would instead be used for phishing delivered through SMS or text messaging.
Incorrect Answers
Answer B is incorrect because Removable-device vector refers to use of USB or other removable media to introduce malware or move data. This could be appropriate elsewhere, but the required function is use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts; that makes Instant-messaging vector the precise choice.
Answer C is incorrect because Watering-hole attack refers to compromise of a site or resource that the intended victims are known to visit. The scenario instead requires use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts, which is why Instant-messaging vector is the better answer; this option serves the different function defined above.
Answer D is incorrect because Smishing refers to phishing delivered through SMS or text messaging. The key mismatch is functional: Instant-messaging vector addresses use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts, the need stated by the question.
Question 12
Which term describes use of USB or other removable media to introduce malware or move data?
- Misinformation
- Default credentials
- Removable-device vector
- Unsecured wireless network
Correct Answer: C
Correct Answer
Answer C is correct because Removable-device vector means use of USB or other removable media to introduce malware or move data. That is the function the question is testing. Unsecured wireless network would instead be used for a wireless environment with weak or absent security controls.
Incorrect Answers
Answer A is incorrect because Misinformation refers to false information that is shared without necessarily intending to deceive. The scenario instead requires use of USB or other removable media to introduce malware or move data, which is why Removable-device vector is the better answer; this option serves the different function defined above.
Answer B is incorrect because Default credentials refers to vendor-supplied or predictable usernames and passwords that have not been changed. The key mismatch is functional: Removable-device vector addresses use of USB or other removable media to introduce malware or move data, the need stated by the question.
Answer D is incorrect because Unsecured wireless network refers to a wireless environment with weak or absent security controls. The scenario instead requires use of USB or other removable media to introduce malware or move data, which is why Removable-device vector is the better answer; this option serves the different function defined above.
Question 13
To expand the externally reachable attack surface, which security approach should be selected?
- Default credentials
- Open service port
- Phishing
- Email-based vector
Correct Answer: B
Correct Answer
Answer B is correct because Open service port means a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. The deciding point is functional fit: this option covers the stated need, while Default credentials addresses vendor-supplied or predictable usernames and passwords that have not been changed.
Incorrect Answers
Answer A is incorrect because Default credentials refers to vendor-supplied or predictable usernames and passwords that have not been changed. The key mismatch is functional: Open service port addresses a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable, the need stated by the question.
Answer C is incorrect because Phishing refers to a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action. The scenario instead requires a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable, which is why Open service port is the better answer; this option serves the different function defined above.
Answer D is incorrect because Email-based vector refers to delivery of malicious links, attachments, requests, or social-engineering content through email. The key mismatch is functional: Open service port addresses a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable, the need stated by the question.
Question 14
To exploit known weaknesses that cannot be remediated through normal updates, which security approach should be selected?
- Phishing
- Misinformation
- Unsupported system
- Brand impersonation
Correct Answer: C
Correct Answer
Answer C is correct because Unsupported system means a system or application that no longer receives security fixes or vendor support. The deciding point is functional fit: this option covers the stated need, while Misinformation addresses false information that is shared without necessarily intending to deceive.
Incorrect Answers
Answer A is incorrect because Phishing refers to a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action. The scenario instead requires a system or application that no longer receives security fixes or vendor support, which is why Unsupported system is the better answer; this option serves the different function defined above.
Answer B is incorrect because Misinformation refers to false information that is shared without necessarily intending to deceive. The scenario instead requires a system or application that no longer receives security fixes or vendor support, which is why Unsupported system is the better answer; this option serves the different function defined above.
Answer D is incorrect because Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users. The concept is valid, but it does not match this stem. The required function is a system or application that no longer receives security fixes or vendor support, which maps to Unsupported system.
Question 15
To target mobile users through messages that appear urgent or familiar, which security approach should be selected?
- SMS-based vector
- Unsecured wireless network
- Brand impersonation
- Removable-device vector
Correct Answer: A
Correct Answer
Answer A is correct because SMS-based vector means delivery of malicious links or deceptive requests through text messaging. That makes it the best answer here; Removable-device vector addresses use of USB or other removable media to introduce malware or move data, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because Unsecured wireless network refers to a wireless environment with weak or absent security controls. The question is not asking for this function. It is testing delivery of malicious links or deceptive requests through text messaging, so SMS-based vector is the stronger fit.
Answer C is incorrect because Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users. That concept can be valid in another scenario, but this question is testing delivery of malicious links or deceptive requests through text messaging; SMS-based vector therefore fits the requirement more directly.
Answer D is incorrect because Removable-device vector refers to use of USB or other removable media to introduce malware or move data. This could be appropriate elsewhere, but the required function is delivery of malicious links or deceptive requests through text messaging; that makes SMS-based vector the precise choice.
Question 16
Which term describes use of a malicious or weaponized file as the initial delivery mechanism?
- Vishing
- File-based vector
- Phishing
- Typosquatting
Correct Answer: B
Correct Answer
Answer B is correct because File-based vector means use of a malicious or weaponized file as the initial delivery mechanism. That makes it the best answer here; Phishing addresses a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Vishing refers to voice-based phishing performed through phone calls or other voice channels. The question is not asking for this function. It is testing use of a malicious or weaponized file as the initial delivery mechanism, so File-based vector is the stronger fit.
Answer C is incorrect because Phishing refers to a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action. The key mismatch is functional: File-based vector addresses use of a malicious or weaponized file as the initial delivery mechanism, the need stated by the question.
Answer D is incorrect because Typosquatting refers to registration or use of look-alike domain names based on common spelling mistakes. The question is not asking for this function. It is testing use of a malicious or weaponized file as the initial delivery mechanism, so File-based vector is the stronger fit.
Question 17
Which term describes compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source?
- Business email compromise
- SMS-based vector
- Supply-chain vector
- Brand impersonation
Correct Answer: C
Correct Answer
Answer C is correct because Supply-chain vector means compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source. That makes it the best answer here; Business email compromise addresses fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Business email compromise refers to fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions. The scenario instead requires compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source, which is why Supply-chain vector is the better answer; this option serves the different function defined above.
Answer B is incorrect because SMS-based vector refers to delivery of malicious links or deceptive requests through text messaging. That concept can be valid in another scenario, but this question is testing compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source; Supply-chain vector therefore fits the requirement more directly.
Answer D is incorrect because Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users. This could be appropriate elsewhere, but the required function is compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source; that makes Supply-chain vector the precise choice.
Question 18
During an attack-surface and threat-vector review, the team has two independent requirements: (1) phishing delivered through SMS or text messaging; and (2) false information deliberately created or spread to deceive. Which TWO choices best satisfy those requirements? Choose TWO.
- Vishing
- Disinformation
- Default credentials
- Unsecured wireless network
- Smishing
Correct Answers: B, E
Correct Answers
Answer B is correct because Disinformation means false information deliberately created or spread to deceive. This option satisfies a specific requirement in the stem; Unsecured wireless network serves a wireless environment with weak or absent security controls and therefore is not interchangeable with it.
Answer E is correct because Smishing means phishing delivered through SMS or text messaging. This selection maps directly to one of the named needs. Unsecured wireless network addresses a wireless environment with weak or absent security controls, so it does not satisfy the same slot.
Incorrect Answers
Answer A is incorrect because Vishing means voice-based phishing performed through phone calls or other voice channels. The required choices are Disinformation, Smishing. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer C is incorrect because Default credentials means vendor-supplied or predictable usernames and passwords that have not been changed. The fixed-count answer set is Disinformation, Smishing; this option does not fill one of those named functions. For example, Disinformation is required for false information deliberately created or spread to deceive.
Answer D is incorrect because Unsecured wireless network means a wireless environment with weak or absent security controls. Every answer slot must map to a stated requirement. The correct set is Disinformation, Smishing, so this option cannot replace one of those selections.
Question 19
The control set for an attack-surface and threat-vector review must address both use of USB or other removable media to introduce malware or move data and compromise of a site or resource that the intended victims are known to visit. Which TWO choices map directly to those needs? Choose TWO.
- Watering-hole attack
- Smishing
- Removable-device vector
- Vulnerable software
- Brand impersonation
Correct Answers: A, C
Correct Answers
Answer A is correct because Watering-hole attack means compromise of a site or resource that the intended victims are known to visit. This option satisfies a specific requirement in the stem; Smishing serves phishing delivered through SMS or text messaging and therefore is not interchangeable with it.
Answer C is correct because Removable-device vector means use of USB or other removable media to introduce malware or move data. It belongs in the fixed-count answer set because it covers one of the stated requirements. Brand impersonation instead serves use of a trusted company’s name, visual identity, or domain-like presence to deceive users and cannot replace this function.
Incorrect Answers
Answer B is incorrect because Smishing means phishing delivered through SMS or text messaging. The fixed-count answer set is Removable-device vector, Watering-hole attack; this option does not fill one of those named functions. For example, Watering-hole attack is required for compromise of a site or resource that the intended victims are known to visit.
Answer D is incorrect because Vulnerable software means software with an exploitable flaw that creates an attack surface. Every answer slot must map to a stated requirement. The correct set is Removable-device vector, Watering-hole attack, so this option cannot replace one of those selections.
Answer E is incorrect because Brand impersonation means use of a trusted company’s name, visual identity, or domain-like presence to deceive users. Every answer slot must map to a stated requirement. The correct set is Removable-device vector, Watering-hole attack, so this option cannot replace one of those selections.
Question 20
During an attack-surface and threat-vector review, three requirements must be addressed: (1) delivery of malicious links or deceptive requests through text messaging; (2) system or application that no longer receives security fixes or vendor support; and (3) pretending to be a trusted person, organization, or system. Which THREE choices best satisfy them? Choose THREE.
- Pretexting
- Instant-messaging vector
- SMS-based vector
- Impersonation
- Open service port
- Unsupported system
Correct Answers: C, D, F
Correct Answers
Answer C is correct because SMS-based vector means delivery of malicious links or deceptive requests through text messaging. This option satisfies a specific requirement in the stem; Instant-messaging vector serves use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts and therefore is not interchangeable with it.
Answer D is correct because Impersonation means pretending to be a trusted person, organization, or system. One required function is exactly what this option provides. Instant-messaging vector may be useful elsewhere, but it is used for use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts.
Answer F is correct because Unsupported system means a system or application that no longer receives security fixes or vendor support. It belongs in the fixed-count answer set because it covers one of the stated requirements. Pretexting instead serves social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Pretexting means social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request. The fixed-count answer set is Unsupported system, SMS-based vector, Impersonation; this option does not fill one of those named functions.
Answer B is incorrect because Instant-messaging vector means use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts. The required choices are Unsupported system, SMS-based vector, Impersonation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because Open service port means a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. The required choices are Unsupported system, SMS-based vector, Impersonation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.