SY0-701: Threats, Vulnerabilities & Mitigations
Threats, Vulnerabilities & Mitigations is one of the skill areas tested on the Security+ (SY0-701) exam. Below are free SY0-701 practice questions with worked answers and a concept diagram — each with a plain-language explanation. Practice the first 10 questions of SY0-701 free, no signup.
The concept, in one picture
2 free SY0-701 Threats, Vulnerabilities & Mitigations questions
An advanced threat group wants to compromise employees of a specific defense contractor. Rather than emailing the staff directly, the attackers plant malicious code on a niche industry news portal that those employees are known to read daily, so that visiting the site infects their workstations. Which technique is being used?
- ✓ Watering-hole attack
- On-path attack
- Typosquatting
- Business email compromise
A watering-hole attack targets a specific group indirectly by compromising a legitimate third-party site the group is known to visit, so victims are infected simply by browsing there. That matches poisoning the industry portal the contractor's staff frequent. An on-path attack requires the attacker to sit between two communicating parties and intercept or alter traffic, which is not described here. Typosquatting relies on victims mistyping a domain and landing on a look-alike the attacker registered, not on compromising a site they intentionally visit. Business email compromise is a social-engineering fraud sent through email, whereas this attack deliberately avoids emailing the targets.
A cloud security team is investigating how internal API keys and service-account passwords keep ending up exposed to the public without any deliberate insider action. Which of the following is the most common source of this kind of accidental credential exposure?
- ✓ Secrets hard-coded and pushed into version-control repositories
- Credential listings sold on dark web marketplaces
- Indicators shared through commercial threat intelligence feeds
- Nation-state adversaries conducting targeted espionage
- Published entries in public vulnerability databases
The most common accidental exposure happens when developers embed secrets (API keys, tokens, passwords) directly in source and then commit and push them to a repository, where automated scanners and attackers can harvest them. This is inadvertent leakage at the origin, which is what the scenario describes. Dark web marketplaces are where already-stolen credentials are traded, not where the accidental leak originates. Threat feeds and vulnerability databases report on exposures after the fact rather than causing them, and nation-state adversaries represent deliberate, targeted attacks rather than unintentional employee mistakes.
Practice SY0-701 free
The first 10 questions of every exam are free. No signup, no email wall.
Start practicing →Get a free SY0-701 study plan by email
A short plan to work through SY0-701 by skill area, plus a note when we add new questions. Optional — the practice above stays free. No spam, unsubscribe anytime.