Threats, attacks and vulnerabilities describes what you are defending against. Master this domain and the rest of Security+ makes sense, because every control exists to reduce a specific threat.
Beginner: the core vocabulary
A threat is anything that could cause harm; a vulnerability is a weakness a threat can exploit; a risk is the likelihood and impact of that exploitation. Threat actors range from unskilled 'script kiddies' to organised crime, hacktivists, insiders and nation-states — each with different motivation, capability and resources.
Intermediate: attack types you must recognise
- Malware: viruses, worms, trojans, ransomware, spyware, rootkits, logic bombs and fileless malware.
- Social engineering: phishing, spear phishing, whaling, vishing, smishing, pretexting and business email compromise.
- Application attacks: SQL injection, cross-site scripting (XSS), buffer overflow, privilege escalation and replay.
- Network attacks: on-path (man-in-the-middle), DNS poisoning, ARP spoofing, DDoS and rogue access points.
Advanced: attacks are layered
Modern intrusions unfold in stages: an initial phishing email delivers a loader, which pulls further malware, which moves laterally using stolen credentials. To defend effectively you need a mental model of how an attack progresses — that is exactly what the Cyber Kill Chain provides.
Interactive explainer: the Cyber Kill Chain
Explore each stage of an intrusion and the defensive control that breaks it. The earlier you break the chain, the cheaper the defence:
The Cyber Kill Chain
The seven stages of an intrusion — and where you can break it.
Tap or hover a part to learn more.
Research the target.
The attacker gathers information — emails, technologies, employees, exposed services — via OSINT and scanning. Defence: minimise public exposure, monitor for scanning.
Check your understanding
1. Blocking a malicious email attachment disrupts which stage?
2. Egress filtering and DNS monitoring most directly disrupt which stage?
Practical example
A finance clerk receives an 'urgent invoice' email (spear phishing) with a macro-enabled document. The macro downloads a trojan (delivery → exploitation → installation); the attacker establishes command and control, harvests credentials and escalates privilege (actions on objectives). Controls that break this chain: email filtering, macro blocking, least privilege, EDR and egress filtering.
Common mistakes
- Confusing a threat with a vulnerability.
- Assuming antivirus stops everything (it misses fileless and novel malware).
- Underestimating the insider threat.
- Treating social engineering as a 'user problem' rather than a control gap.
Best practices
Defence in depth, user-awareness training, patching, least privilege, network segmentation, and continuous monitoring so an initial compromise never becomes a full breach. See Secure Architecture & Cloud for the design side and Security Operations for detection.
What employers expect
You can categorise an attack, explain likely indicators of compromise, map it to a kill-chain stage, and recommend proportionate mitigations — not just name the attack.
Technical interview questions
- What is the difference between a threat, a vulnerability and a risk?
- Explain the difference between a worm and a virus.
- Walk me through how a phishing attack can lead to a full network compromise.
- What indicators would suggest a machine is infected with ransomware?
- Describe the cyber kill chain and a defensive control for each stage.
Behavioural interview questions
- Tell me about a time you spotted something suspicious and raised it.
- Describe how you would explain a security risk to a non-technical colleague.
Practice questions
- Which attack manipulates a user by pretending to be IT support over the phone? (Vishing / pretexting)
- Which malware encrypts files and demands payment? (Ransomware)
- Which attack injects script into a trusted website viewed by others? (XSS)
- Cutting off malware's link to attacker infrastructure disrupts which kill-chain stage? (Command & Control)
Where this fits in your Security+ pathway
This domain is one part of the CompTIA Security+ study hub. When you're confident here, continue with Cryptography & PKI to keep building toward the full exam.
Practise with Missiora
- AI Interview™ — rehearse Security+ style questions on this topic and get scored feedback.
- Career Coach™ — turn this knowledge into a study-to-job plan.
- Job Intelligence™ — see which of these skills real security adverts demand.
