Missiora
Security+ Domain: Threats, Attacks & Vulnerabilities

IT & Cyber Certifications

Security+ Domain: Threats, Attacks & Vulnerabilities

3 min readPublished 22 Jul 2026

Threats, attacks and vulnerabilities describes what you are defending against. Master this domain and the rest of Security+ makes sense, because every control exists to reduce a specific threat.

Beginner: the core vocabulary

A threat is anything that could cause harm; a vulnerability is a weakness a threat can exploit; a risk is the likelihood and impact of that exploitation. Threat actors range from unskilled 'script kiddies' to organised crime, hacktivists, insiders and nation-states — each with different motivation, capability and resources.

Intermediate: attack types you must recognise

  • Malware: viruses, worms, trojans, ransomware, spyware, rootkits, logic bombs and fileless malware.
  • Social engineering: phishing, spear phishing, whaling, vishing, smishing, pretexting and business email compromise.
  • Application attacks: SQL injection, cross-site scripting (XSS), buffer overflow, privilege escalation and replay.
  • Network attacks: on-path (man-in-the-middle), DNS poisoning, ARP spoofing, DDoS and rogue access points.

Advanced: attacks are layered

Modern intrusions unfold in stages: an initial phishing email delivers a loader, which pulls further malware, which moves laterally using stolen credentials. To defend effectively you need a mental model of how an attack progresses — that is exactly what the Cyber Kill Chain provides.

Interactive explainer: the Cyber Kill Chain

Explore each stage of an intrusion and the defensive control that breaks it. The earlier you break the chain, the cheaper the defence:

Interactive explainer

The Cyber Kill Chain

The seven stages of an intrusion — and where you can break it.

1Reconnaissance2Weaponization3Delivery4Exploitation5Installation6Command & Control7Actions on Objectives

Tap or hover a part to learn more.

Reconnaissance

Research the target.

The attacker gathers information — emails, technologies, employees, exposed services — via OSINT and scanning. Defence: minimise public exposure, monitor for scanning.

Check your understanding

1. Blocking a malicious email attachment disrupts which stage?

2. Egress filtering and DNS monitoring most directly disrupt which stage?

Practise this in AI Interview™

Practical example

A finance clerk receives an 'urgent invoice' email (spear phishing) with a macro-enabled document. The macro downloads a trojan (delivery → exploitation → installation); the attacker establishes command and control, harvests credentials and escalates privilege (actions on objectives). Controls that break this chain: email filtering, macro blocking, least privilege, EDR and egress filtering.

Common mistakes

  • Confusing a threat with a vulnerability.
  • Assuming antivirus stops everything (it misses fileless and novel malware).
  • Underestimating the insider threat.
  • Treating social engineering as a 'user problem' rather than a control gap.

Best practices

Defence in depth, user-awareness training, patching, least privilege, network segmentation, and continuous monitoring so an initial compromise never becomes a full breach. See Secure Architecture & Cloud for the design side and Security Operations for detection.

What employers expect

You can categorise an attack, explain likely indicators of compromise, map it to a kill-chain stage, and recommend proportionate mitigations — not just name the attack.

Technical interview questions

  1. What is the difference between a threat, a vulnerability and a risk?
  2. Explain the difference between a worm and a virus.
  3. Walk me through how a phishing attack can lead to a full network compromise.
  4. What indicators would suggest a machine is infected with ransomware?
  5. Describe the cyber kill chain and a defensive control for each stage.

Behavioural interview questions

  1. Tell me about a time you spotted something suspicious and raised it.
  2. Describe how you would explain a security risk to a non-technical colleague.

Practice questions

  1. Which attack manipulates a user by pretending to be IT support over the phone? (Vishing / pretexting)
  2. Which malware encrypts files and demands payment? (Ransomware)
  3. Which attack injects script into a trusted website viewed by others? (XSS)
  4. Cutting off malware's link to attacker infrastructure disrupts which kill-chain stage? (Command & Control)

Where this fits in your Security+ pathway

This domain is one part of the CompTIA Security+ study hub. When you're confident here, continue with Cryptography & PKI to keep building toward the full exam.

Practise with Missiora

Interview Intelligence

How this topic actually shows up in interviews — and how to demonstrate you understand it.

Why employers ask about this

Threats are the 'why' behind every control; interviewers test whether you can recognise attacks and reason about likelihood and impact.

Technical questions
What's the difference between a threat, a vulnerability and a risk?+

A vulnerability is a weakness; a threat is something that could exploit it; risk is the likelihood and impact of that happening.

What is phishing and how do you defend against it?+

Social-engineering email tricking users into revealing data or clicking malware; defend with awareness training, email filtering, MFA and reporting processes.

Behavioural questions
Describe how you'd explain a security threat to a non-technical user.+

Show empathy and clarity — use an analogy, avoid jargon, and give the user one clear action to take.

Real-world scenarios
“Several staff report their passwords 'stopped working' overnight.”+

Expected answer: Suspect a possible credential attack or breach; escalate, force resets, enable MFA and investigate for compromise.

Common candidate mistakes
  • Confusing a vulnerability with a threat.
  • Underestimating social engineering versus technical attacks.

Employability Intelligence

Where this knowledge takes you — the jobs, skills and certifications it feeds into.

Relevant roles
SOC AnalystThreat AnalystSecurity Analyst
Skills you're proving
Threat identificationSocial engineering awarenessVulnerability conceptsRisk reasoning
Recommended certifications
Career progression

Security Analyst → SOC Analyst → Threat/Vulnerability Analyst.

What employers expect

That you can identify common attacks and prioritise them by risk.

Frequently asked questions

How much of Security+ is about threats and attacks?

Threats, attacks and vulnerabilities is one of the largest weighted areas of SY0-701, so it rewards thorough study and hands-on recognition of attack indicators.

Do I need to memorise every malware type?

You should be able to recognise and distinguish the main categories (ransomware, trojan, worm, rootkit, spyware, fileless) and describe their typical behaviour, rather than memorise obscure examples.

What is the difference between a threat, a vulnerability and a risk?

A threat is something that could cause harm (such as malware), a vulnerability is a weakness it could exploit, and risk is the likelihood and impact of that threat exploiting the vulnerability. Security+ expects you to use these terms precisely.

Related guides

Practise what you've learned

Turn this guide into real, evidenced progress

Missiora helps you measure, improve and evidence the capabilities employers actually value — start with the tools best suited to this topic.

M
Published by
Missiora

Missiora is an AI Employability Intelligence platform. Our resources are researched and reviewed by the Missiora team to help you measure, improve and prove your career readiness.