Threats, Vulnerabilities & Mitigations: what Security+ tests and how to prepare
The domain most people expect the exam to be about. It covers threat actors and their motivations, attack surfaces, the vulnerability types you are expected to recognise, and the mitigations that answer them.
What this domain covers
The list below follows the published exam objectives for SY0-701. Depth matters more than breadth here: the exam asks you to apply these ideas to a scenario, not to recite them.
- Threat actor types and attributes — nation-state, unskilled attacker, hacktivist, insider threat, organised crime, shadow IT — and their motivations.
- Threat vectors and attack surfaces: message-based, image-based, file-based, removable device, vulnerable software, unsupported systems, supply chain.
- Vulnerability types across application, operating system, web, hardware, virtualisation, cloud, supply chain and cryptography.
- Indicators of malicious activity: malware, physical, network, application and cryptographic attacks.
- Mitigation techniques including segmentation, access control, isolation, hardening, patching, encryption and monitoring.
Where candidates lose marks
- Matching an attack to a plausible mitigation rather than the best one. Several options usually help; the exam wants the one that addresses the specific weakness described.
- Reading threat actor questions as trivia. The attribute that matters — resources, sophistication, motivation — is what determines the correct answer, not the label.
- Overlooking that "unsupported systems and applications" is its own vector. It appears more often than candidates expect.
Practise reading the scenario for the specific weakness before looking at the options. The most common error in this domain is recognising the attack family correctly and then picking a control that mitigates a different member of it.
Find out if this domain is your weak one
20 free Security+ questions, no card required. Readiness is reported per domain, so you can see whether Threats, Vulnerabilities & Mitigations is where your revision should go.