CompTIA Security+ SY0-701 Threat Vectors and Attack Surfaces Practice Test 2

 

Topic 06 Practice Test 2 covers Threat Vectors and Attack Surfaces for CompTIA Security+ SY0-701 and maps to objective 2.2: Explain common threat vectors and attack surfaces. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

Which term describes phishing delivered through SMS or text messaging?

  1. Pretexting
  2. Brand impersonation
  3. Watering-hole attack
  4. Smishing

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Smishing means phishing delivered through SMS or text messaging. That is the function the question is testing. Pretexting would instead be used for social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request.

Incorrect Answers

 

Answer A is incorrect because Pretexting refers to social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request. The key mismatch is functional: Smishing addresses phishing delivered through SMS or text messaging, the need stated by the question.

Answer B is incorrect because Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users. This could be appropriate elsewhere, but the required function is phishing delivered through SMS or text messaging; that makes Smishing the precise choice.

Answer C is incorrect because Watering-hole attack refers to compromise of a site or resource that the intended victims are known to visit. The key mismatch is functional: Smishing addresses phishing delivered through SMS or text messaging, the need stated by the question.

 

Question 2

What is a wireless environment with weak or absent security controls?

  1. Pretexting
  2. Open service port
  3. Unsecured wireless network
  4. Typosquatting

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Unsecured wireless network means a wireless environment with weak or absent security controls. That makes it the best answer here; Typosquatting addresses registration or use of look-alike domain names based on common spelling mistakes, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Pretexting refers to social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request. That concept can be valid in another scenario, but this question is testing a wireless environment with weak or absent security controls; Unsecured wireless network therefore fits the requirement more directly.

Answer B is incorrect because Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. This could be appropriate elsewhere, but the required function is a wireless environment with weak or absent security controls; that makes Unsecured wireless network the precise choice.

Answer D is incorrect because Typosquatting refers to registration or use of look-alike domain names based on common spelling mistakes. That concept can be valid in another scenario, but this question is testing a wireless environment with weak or absent security controls; Unsecured wireless network therefore fits the requirement more directly. This question specifically tests the requirement represented by Unsecured wireless network.

 

Question 3

A review during an attack-surface and threat-vector review identifies two gaps. One requires compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source. The other requires false information that is shared without necessarily intending to deceive. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Open service port
  2. Typosquatting
  3. Supply-chain vector
  4. Unsupported system
  5. Misinformation

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because Supply-chain vector means compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source. This option satisfies a specific requirement in the stem; Open service port serves a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable and therefore is not interchangeable with it.

Answer E is correct because Misinformation means false information that is shared without necessarily intending to deceive. This option satisfies a specific requirement in the stem; Open service port serves a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Open service port means a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. The fixed-count answer set is Supply-chain vector, Misinformation; this option does not fill one of those named functions.

Answer B is incorrect because Typosquatting means registration or use of look-alike domain names based on common spelling mistakes. The required choices are Supply-chain vector, Misinformation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Unsupported system means a system or application that no longer receives security fixes or vendor support. The required choices are Supply-chain vector, Misinformation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 4

A review during an attack-surface and threat-vector review identifies two gaps. One requires use of USB or other removable media to introduce malware or move data. The other requires wireless environment with weak or absent security controls. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Removable-device vector
  2. Unsecured wireless network
  3. SMS-based vector
  4. Voice-call vector
  5. Default credentials

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Removable-device vector means use of USB or other removable media to introduce malware or move data. One required function is exactly what this option provides. Default credentials may be useful elsewhere, but it is used for vendor-supplied or predictable usernames and passwords that have not been changed.

Answer B is correct because Unsecured wireless network means a wireless environment with weak or absent security controls. The fixed-count item needs this function in the answer set. Default credentials covers vendor-supplied or predictable usernames and passwords that have not been changed, a different requirement.

Incorrect Answers

 

Answer C is incorrect because SMS-based vector means delivery of malicious links or deceptive requests through text messaging. The scenario calls for Unsecured wireless network, Removable-device vector. Selecting this option would leave one of those required functions uncovered. For example, Unsecured wireless network is required for a wireless environment with weak or absent security controls.

Answer D is incorrect because Voice-call vector means use of spoken interaction to deceive a person into revealing information or taking an unsafe action. Every answer slot must map to a stated requirement. The correct set is Unsecured wireless network, Removable-device vector, so this option cannot replace one of those selections.

Answer E is incorrect because Default credentials means vendor-supplied or predictable usernames and passwords that have not been changed. The scenario calls for Unsecured wireless network, Removable-device vector. Selecting this option would leave one of those required functions uncovered.

 

Question 5

Two requirements remain open in an attack-surface and threat-vector review: phishing delivered through SMS or text messaging; pretending to be a trusted person, organization, or system. Which TWO options close those specific gaps? Choose TWO.

  1. Disinformation
  2. Smishing
  3. Open service port
  4. Unsupported system
  5. Impersonation

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because Smishing means phishing delivered through SMS or text messaging. The fixed-count item needs this function in the answer set. Disinformation covers false information deliberately created or spread to deceive, a different requirement.

Answer E is correct because Impersonation means pretending to be a trusted person, organization, or system. The fixed-count item needs this function in the answer set. Unsupported system covers a system or application that no longer receives security fixes or vendor support, a different requirement.

Incorrect Answers

 

Answer A is incorrect because Disinformation means false information deliberately created or spread to deceive. The fixed-count answer set is Impersonation, Smishing; this option does not fill one of those named functions. For example, Smishing is required for phishing delivered through SMS or text messaging.

Answer C is incorrect because Open service port means a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. The fixed-count answer set is Impersonation, Smishing; this option does not fill one of those named functions.

Answer D is incorrect because Unsupported system means a system or application that no longer receives security fixes or vendor support. The fixed-count answer set is Impersonation, Smishing; this option does not fill one of those named functions. For example, Smishing is required for phishing delivered through SMS or text messaging.

 

Question 6

Which term describes use of spoken interaction to deceive a person into revealing information or taking an unsafe action?

  1. Voice-call vector
  2. Phishing
  3. Vishing
  4. Brand impersonation

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Voice-call vector means use of spoken interaction to deceive a person into revealing information or taking an unsafe action. This is the precise fit for the scenario. Phishing serves the different purpose of a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action.

Incorrect Answers

 

Answer B is incorrect because Phishing refers to a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action. The question is not asking for this function. It is testing use of spoken interaction to deceive a person into revealing information or taking an unsafe action, so Voice-call vector is the stronger fit.

Answer C is incorrect because Vishing refers to voice-based phishing performed through phone calls or other voice channels. The question is not asking for this function. It is testing use of spoken interaction to deceive a person into revealing information or taking an unsafe action, so Voice-call vector is the stronger fit.

Answer D is incorrect because Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users. That concept can be valid in another scenario, but this question is testing use of spoken interaction to deceive a person into revealing information or taking an unsafe action; Voice-call vector therefore fits the requirement more directly.

 

Question 7

Which system or application no longer receives security fixes or vendor support?

  1. Impersonation
  2. Unsupported system
  3. Watering-hole attack
  4. Voice-call vector

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Unsupported system means a system or application that no longer receives security fixes or vendor support. The requirement maps directly to this function, whereas Watering-hole attack is aimed at compromise of a site or resource that the intended victims are known to visit.

Incorrect Answers

 

Answer A is incorrect because Impersonation refers to pretending to be a trusted person, organization, or system. The concept is valid, but it does not match this stem. The required function is a system or application that no longer receives security fixes or vendor support, which maps to Unsupported system.

Answer C is incorrect because Watering-hole attack refers to compromise of a site or resource that the intended victims are known to visit. The scenario instead requires a system or application that no longer receives security fixes or vendor support, which is why Unsupported system is the better answer; this option serves the different function defined above.

Answer D is incorrect because Voice-call vector refers to use of spoken interaction to deceive a person into revealing information or taking an unsafe action. That concept can be valid in another scenario, but this question is testing a system or application that no longer receives security fixes or vendor support; Unsupported system therefore fits the requirement more directly.

 

Question 8

To make malicious content appear to originate from a legitimate brand, which security approach should be selected?

  1. Supply-chain vector
  2. Misinformation
  3. Brand impersonation
  4. Email-based vector

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Brand impersonation means use of a trusted company’s name, visual identity, or domain-like presence to deceive users. That makes it the best answer here; Email-based vector addresses delivery of malicious links, attachments, requests, or social-engineering content through email, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Supply-chain vector refers to compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source. The key mismatch is functional: Brand impersonation addresses use of a trusted company’s name, visual identity, or domain-like presence to deceive users, the need stated by the question.

Answer B is incorrect because Misinformation refers to false information that is shared without necessarily intending to deceive. The scenario instead requires use of a trusted company’s name, visual identity, or domain-like presence to deceive users, which is why Brand impersonation is the better answer; this option serves the different function defined above.

Answer D is incorrect because Email-based vector refers to delivery of malicious links, attachments, requests, or social-engineering content through email. The question is not asking for this function. It is testing use of a trusted company’s name, visual identity, or domain-like presence to deceive users, so Brand impersonation is the stronger fit.

 

Question 9

To persuade a victim through spoken social engineering, which security approach should be selected?

  1. Typosquatting
  2. Supply-chain vector
  3. Open service port
  4. Vishing

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Vishing means voice-based phishing performed through phone calls or other voice channels. The deciding point is functional fit: this option covers the stated need, while Open service port addresses a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.

Incorrect Answers

 

Answer A is incorrect because Typosquatting refers to registration or use of look-alike domain names based on common spelling mistakes. The scenario instead requires voice-based phishing performed through phone calls or other voice channels, which is why Vishing is the better answer; this option serves the different function defined above.

Answer B is incorrect because Supply-chain vector refers to compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source. That concept can be valid in another scenario, but this question is testing voice-based phishing performed through phone calls or other voice channels; Vishing therefore fits the requirement more directly.

Answer C is incorrect because Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. The concept is valid, but it does not match this stem. The required function is voice-based phishing performed through phone calls or other voice channels, which maps to Vishing.

 

Question 10

Which term describes use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts?

  1. Default credentials
  2. SMS-based vector
  3. Impersonation
  4. Instant-messaging vector

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Instant-messaging vector means use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts. That makes it the best answer here; SMS-based vector addresses delivery of malicious links or deceptive requests through text messaging, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Default credentials refers to vendor-supplied or predictable usernames and passwords that have not been changed. This could be appropriate elsewhere, but the required function is use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts; that makes Instant-messaging vector the precise choice.

Answer B is incorrect because SMS-based vector refers to delivery of malicious links or deceptive requests through text messaging. This could be appropriate elsewhere, but the required function is use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts; that makes Instant-messaging vector the precise choice.

Answer C is incorrect because Impersonation refers to pretending to be a trusted person, organization, or system. The question is not asking for this function. It is testing use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts, so Instant-messaging vector is the stronger fit.

 

Question 11

Which term describes delivery of malicious links, attachments, requests, or social-engineering content through email?

  1. Email-based vector
  2. File-based vector
  3. Watering-hole attack
  4. Supply-chain vector

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Email-based vector means delivery of malicious links, attachments, requests, or social-engineering content through email. This is the precise fit for the scenario. File-based vector serves the different purpose of use of a malicious or weaponized file as the initial delivery mechanism.

Incorrect Answers

 

Answer B is incorrect because File-based vector refers to use of a malicious or weaponized file as the initial delivery mechanism. The concept is valid, but it does not match this stem. The required function is delivery of malicious links, attachments, requests, or social-engineering content through email, which maps to Email-based vector.

Answer C is incorrect because Watering-hole attack refers to compromise of a site or resource that the intended victims are known to visit. The question is not asking for this function. It is testing delivery of malicious links, attachments, requests, or social-engineering content through email, so Email-based vector is the stronger fit.

Answer D is incorrect because Supply-chain vector refers to compromise introduced through a vendor, supplier, software dependency, service provider, or hardware source. The concept is valid, but it does not match this stem. The required function is delivery of malicious links, attachments, requests, or social-engineering content through email, which maps to Email-based vector.

 

Question 12

The control set for an attack-surface and threat-vector review must address both delivery of malicious links or deceptive requests through text messaging and use of spoken interaction to deceive a person into revealing information or taking an unsafe action. Which TWO choices map directly to those needs? Choose TWO.

  1. Open service port
  2. Misinformation
  3. Default credentials
  4. SMS-based vector
  5. Voice-call vector

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because SMS-based vector means delivery of malicious links or deceptive requests through text messaging. One required function is exactly what this option provides. Default credentials may be useful elsewhere, but it is used for vendor-supplied or predictable usernames and passwords that have not been changed.

Answer E is correct because Voice-call vector means use of spoken interaction to deceive a person into revealing information or taking an unsafe action. One required function is exactly what this option provides. Misinformation may be useful elsewhere, but it is used for false information that is shared without necessarily intending to deceive.

Incorrect Answers

 

Answer A is incorrect because Open service port means a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. The required choices are SMS-based vector, Voice-call vector. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer B is incorrect because Misinformation means false information that is shared without necessarily intending to deceive. The question requires exactly 2 selections: SMS-based vector, Voice-call vector. This option falls outside that required set. For example, SMS-based vector is required for delivery of malicious links or deceptive requests through text messaging.

Answer C is incorrect because Default credentials means vendor-supplied or predictable usernames and passwords that have not been changed. The scenario calls for SMS-based vector, Voice-call vector. Selecting this option would leave one of those required functions uncovered. For example, Voice-call vector is required for use of spoken interaction to deceive a person into revealing information or taking an unsafe action.

 

Question 13

Which term describes vendor-supplied or predictable usernames and passwords that have not been changed?

  1. Default credentials
  2. Disinformation
  3. Instant-messaging vector
  4. Phishing

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Default credentials means vendor-supplied or predictable usernames and passwords that have not been changed. The requirement maps directly to this function, whereas Instant-messaging vector is aimed at use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts.

Incorrect Answers

 

Answer B is incorrect because Disinformation refers to false information deliberately created or spread to deceive. The key mismatch is functional: Default credentials addresses vendor-supplied or predictable usernames and passwords that have not been changed, the need stated by the question.

Answer C is incorrect because Instant-messaging vector refers to use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts. That concept can be valid in another scenario, but this question is testing vendor-supplied or predictable usernames and passwords that have not been changed; Default credentials therefore fits the requirement more directly.

Answer D is incorrect because Phishing refers to a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action. The question is not asking for this function. It is testing vendor-supplied or predictable usernames and passwords that have not been changed, so Default credentials is the stronger fit.

 

Question 14

To reach users through a widely trusted business communication channel, which security approach should be selected?

  1. Open service port
  2. Email-based vector
  3. Voice-call vector
  4. Vulnerable software

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Email-based vector means delivery of malicious links, attachments, requests, or social-engineering content through email. The deciding point is functional fit: this option covers the stated need, while Voice-call vector addresses use of spoken interaction to deceive a person into revealing information or taking an unsafe action.

Incorrect Answers

 

Answer A is incorrect because Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. That concept can be valid in another scenario, but this question is testing delivery of malicious links, attachments, requests, or social-engineering content through email; Email-based vector therefore fits the requirement more directly.

Answer C is incorrect because Voice-call vector refers to use of spoken interaction to deceive a person into revealing information or taking an unsafe action. The key mismatch is functional: Email-based vector addresses delivery of malicious links, attachments, requests, or social-engineering content through email, the need stated by the question.

Answer D is incorrect because Vulnerable software refers to software with an exploitable flaw that creates an attack surface. The key mismatch is functional: Email-based vector addresses delivery of malicious links, attachments, requests, or social-engineering content through email, the need stated by the question.

 

Question 15

Which deceptive message is designed to trick a target into revealing information, opening content, or taking an unsafe action?

  1. Business email compromise
  2. Phishing
  3. Pretexting
  4. Open service port

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Phishing means a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action. That makes it the best answer here; Business email compromise addresses fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Business email compromise refers to fraud that impersonates or compromises business email identities to induce payments, data disclosure, or other actions. The question is not asking for this function. It is testing a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action, so Phishing is the stronger fit.

Answer C is incorrect because Pretexting refers to social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request. This could be appropriate elsewhere, but the required function is a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action; that makes Phishing the precise choice.

Answer D is incorrect because Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. The key mismatch is functional: Phishing addresses a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action, the need stated by the question.

 

Question 16

To gain access or execute code by exploiting an unpatched weakness, which security approach should be selected?

  1. Vishing
  2. Brand impersonation
  3. Vulnerable software
  4. File-based vector

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Vulnerable software means software with an exploitable flaw that creates an attack surface. This is the precise fit for the scenario. Vishing serves the different purpose of voice-based phishing performed through phone calls or other voice channels.

Incorrect Answers

 

Answer A is incorrect because Vishing refers to voice-based phishing performed through phone calls or other voice channels. The question is not asking for this function. It is testing software with an exploitable flaw that creates an attack surface, so Vulnerable software is the stronger fit.

Answer B is incorrect because Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users. The key mismatch is functional: Vulnerable software addresses software with an exploitable flaw that creates an attack surface, the need stated by the question.

Answer D is incorrect because File-based vector refers to use of a malicious or weaponized file as the initial delivery mechanism. The question is not asking for this function. It is testing software with an exploitable flaw that creates an attack surface, so Vulnerable software is the stronger fit.

 

Question 17

To gain access by trying well-known factory credentials, which security approach should be selected?

  1. Brand impersonation
  2. Default credentials
  3. Open service port
  4. File-based vector

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Default credentials means vendor-supplied or predictable usernames and passwords that have not been changed. The deciding point is functional fit: this option covers the stated need, while Open service port addresses a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable.

Incorrect Answers

 

Answer A is incorrect because Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users. The scenario instead requires vendor-supplied or predictable usernames and passwords that have not been changed, which is why Default credentials is the better answer; this option serves the different function defined above.

Answer C is incorrect because Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. The scenario instead requires vendor-supplied or predictable usernames and passwords that have not been changed, which is why Default credentials is the better answer; this option serves the different function defined above.

Answer D is incorrect because File-based vector refers to use of a malicious or weaponized file as the initial delivery mechanism. The question is not asking for this function. It is testing vendor-supplied or predictable usernames and passwords that have not been changed, so Default credentials is the stronger fit.

 

Question 18

To make a deceptive request seem legitimate through a convincing story, which security approach should be selected?

  1. Pretexting
  2. Instant-messaging vector
  3. Brand impersonation
  4. Open service port

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Pretexting means social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request. The requirement maps directly to this function, whereas Instant-messaging vector is aimed at use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts.

Incorrect Answers

 

Answer B is incorrect because Instant-messaging vector refers to use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts. The concept is valid, but it does not match this stem. The required function is social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request, which maps to Pretexting.

Answer C is incorrect because Brand impersonation refers to use of a trusted company’s name, visual identity, or domain-like presence to deceive users. The key mismatch is functional: Pretexting addresses social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request, the need stated by the question.

Answer D is incorrect because Open service port refers to a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. The scenario instead requires social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request, which is why Pretexting is the better answer; this option serves the different function defined above.

 

Question 19

Reviewers working through an attack-surface and threat-vector review identify three separate needs: software with an exploitable flaw that creates an attack surface; system or application that no longer receives security fixes or vendor support; social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request. Which THREE choices map to those needs? Choose THREE.

  1. Email-based vector
  2. Vulnerable software
  3. Unsupported system
  4. Pretexting
  5. File-based vector
  6. Removable-device vector

Correct Answers: B, C, D

Correct Answers

 

 

Answer B is correct because Vulnerable software means software with an exploitable flaw that creates an attack surface. It belongs in the fixed-count answer set because it covers one of the stated requirements. File-based vector instead serves use of a malicious or weaponized file as the initial delivery mechanism and cannot replace this function.

Answer C is correct because Unsupported system means a system or application that no longer receives security fixes or vendor support. The fixed-count item needs this function in the answer set. Removable-device vector covers use of USB or other removable media to introduce malware or move data, a different requirement.

Answer D is correct because Pretexting means social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request. This selection maps directly to one of the named needs. Removable-device vector addresses use of USB or other removable media to introduce malware or move data, so it does not satisfy the same slot.

Incorrect Answers

 

Answer A is incorrect because Email-based vector means delivery of malicious links, attachments, requests, or social-engineering content through email. Every answer slot must map to a stated requirement. The correct set is Vulnerable software, Pretexting, Unsupported system, so this option cannot replace one of those selections.

Answer E is incorrect because File-based vector means use of a malicious or weaponized file as the initial delivery mechanism. Every answer slot must map to a stated requirement. The correct set is Vulnerable software, Pretexting, Unsupported system, so this option cannot replace one of those selections.

Answer F is incorrect because Removable-device vector means use of USB or other removable media to introduce malware or move data. The required choices are Vulnerable software, Pretexting, Unsupported system. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 20

Two requirements remain open in an attack-surface and threat-vector review: deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action; social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request. Which TWO options close those specific gaps? Choose TWO.

  1. Pretexting
  2. Phishing
  3. Vulnerable software
  4. Open service port
  5. Instant-messaging vector

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Pretexting means social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request. The fixed-count item needs this function in the answer set. Vulnerable software covers software with an exploitable flaw that creates an attack surface, a different requirement.

Answer B is correct because Phishing means a deceptive message designed to trick a target into revealing information, opening content, or taking an unsafe action. The fixed-count item needs this function in the answer set. Open service port covers a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable, a different requirement.

Incorrect Answers

 

Answer C is incorrect because Vulnerable software means software with an exploitable flaw that creates an attack surface. The scenario calls for Phishing, Pretexting. Selecting this option would leave one of those required functions uncovered. For example, Pretexting is required for social engineering built around a fabricated scenario that gives the attacker a plausible reason for a request.

Answer D is incorrect because Open service port means a reachable network port exposing a service that may be unnecessary, misconfigured, or vulnerable. The required choices are Phishing, Pretexting. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Instant-messaging vector means use of chat or collaboration platforms to deliver malicious content or impersonate trusted contacts. The fixed-count answer set is Phishing, Pretexting; this option does not fill one of those named functions.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!