🇺🇸 CompTIA Security+ · subject
CompTIA Security+ Threats, Vulnerabilities, and Mitigations Syllabus
Every chapter and topic of Threats, Vulnerabilities, and Mitigations examined in CompTIA Security+ — 5 chapters, 22 topics and 60 sub-topics, plus 65 flashcards written against it.
Threats, Vulnerabilities, and Mitigations syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Threats, Vulnerabilities, and Mitigations in CompTIA Security+, not a summary of it.
-
Threat Actors and Motivations
3 topics- Threat Actor Types
- Nation-state and advanced persistent threats
- Unskilled attackers and hacktivists
- Insider threats
- Organized crime and shadow IT
- Threat Actor Attributes
- Internal vs external
- Resources/funding and level of sophistication
- Motivations
- Data exfiltration and espionage
- Financial gain and blackmail
- Disruption, chaos, and ideology
- Threat Actor Types
-
Threat Vectors and Attack Surfaces
4 topics- Message-Based Vectors
- Email and SMS/instant messaging
- Voice calls
- Technical Vectors
- Image-based and file-based
- Removable devices and vulnerable software
- Unsupported systems and open service ports
- Default credentials
- Supply Chain Vectors
- Managed service providers (MSPs)
- Vendors and suppliers
- Human and Social Engineering Vectors
- Phishing, vishing, and smishing
- Pretexting and impersonation
- Business email compromise
- Watering hole and typosquatting
- Message-Based Vectors
-
Vulnerability Types
6 topics- Application Vulnerabilities
- Memory injection and buffer overflow
- Race conditions (TOC/TOU)
- Malicious update
- Web-Based Vulnerabilities
- SQL injection (SQLi)
- Cross-site scripting (XSS)
- Operating System and Hardware Vulnerabilities
- Firmware and end-of-life hardware
- Legacy systems
- Virtualization and Cloud Vulnerabilities
- VM escape and resource reuse
- Cloud-specific misconfiguration
- Supply Chain and Cryptographic Vulnerabilities
- Service provider and hardware/software providers
- Misconfiguration and zero-day
- Mobile Device Vulnerabilities
- Side loading
- Jailbreaking
- Application Vulnerabilities
-
Malicious Activity and Indicators
5 topics- Malware Attacks
- Ransomware and trojans
- Worms and spyware
- Rootkits, logic bombs, and keyloggers
- Bloatware and viruses
- Physical and Network Attacks
- Brute force (physical) and RFID cloning
- DDoS (amplified and reflected)
- DNS attacks and wireless attacks
- On-path and credential replay
- Application Attacks
- Injection and privilege escalation
- Forgery and directory traversal
- Cryptographic and Password Attacks
- Downgrade, collision, and birthday attacks
- Spraying and brute force
- Indicators of Compromise
- Account lockout and concurrent session usage
- Impossible travel and resource consumption
- Missing logs and out-of-cycle logging
- Malware Attacks
-
Mitigation Techniques
4 topics- Segmentation and Access Control
- Network segmentation
- Access control lists and permissions
- Application Allow Listing and Isolation
- Application allow/deny lists
- Isolation and sandboxing
- System Hardening Targets
- Workstations, servers, and mobile devices
- Switches, routers, and cloud infrastructure
- Embedded systems, ICS/SCADA, IoT, RTOS
- Hardening Techniques
- Encryption and endpoint protection
- Host-based firewall and HIPS
- Disabling ports/protocols and changing default passwords
- Removal of unnecessary software
- Segmentation and Access Control
Threats, Vulnerabilities, and Mitigations flashcards for CompTIA Security+
18 of 65 cards from the Threats, Vulnerabilities, and Mitigations deck — real questions with worked answers.
What are the main types of threat actors recognized in CompTIA Security+?
Nation-state actors, unskilled attackers (script kiddies), hacktivists, insider threats, organized crime, and shadow IT.
What distinguishes a nation-state threat actor from other actors?
They are highly resourced, well-funded, sophisticated, and often pursue Advanced Persistent Threats (APTs) for espionage, ideological, or strategic goals.
What is an Advanced Persistent Threat (APT)?
A sophisticated, long-term attack (usually by nation-states) where an intruder gains and maintains undetected access to a network over an extended period.
What is a hacktivist and what motivates them?
An attacker driven by ideological, political, social, or philosophical beliefs rather than financial gain, often using attacks to make a statement.
What is an unskilled attacker (script kiddie)?
A low-skilled actor who uses existing tools, scripts, and exploits created by others without understanding the underlying technology.
What is shadow IT?
Hardware, software, or cloud services used within an organization without explicit IT department approval, creating unmanaged security risks.
What are the key attributes used to classify threat actors?
Internal vs. external, resources/funding level, and level of sophistication/capability.
Compare internal vs. external threat actors.
Internal actors (insiders) have authorized access and knowledge of systems; external actors must breach perimeter defenses from outside the organization.
What are the primary motivations behind threat actor attacks?
Data exfiltration, espionage, financial gain, blackmail, service disruption, ideology/philosophical beliefs, revenge, war, and ethical (hacktivism) reasons.
What motivation typically drives organized crime threat actors?
Financial gain through activities like ransomware, fraud, data theft, and extortion.
What is a message-based threat vector?
An attack delivered through email, SMS (smishing), or instant messaging, often carrying phishing links or malicious attachments.
What is a technical (technology-based) threat vector? Give examples.
An attack exploiting technology itself, such as unsecured networks, open service ports, default credentials, or vulnerable software/firmware.
What is a supply chain attack vector?
Compromising an organization by targeting its less-secure suppliers, vendors, managed service providers (MSPs), or hardware/software components.
Why are managed service providers (MSPs) attractive supply chain targets?
Because compromising one MSP can give attackers access to many downstream client organizations that trust it.
What is social engineering?
Manipulating people into divulging confidential information or performing actions that compromise security, exploiting human psychology rather than technical flaws.
What is phishing?
A social engineering attack using fraudulent emails or messages that appear legitimate to trick victims into revealing data or clicking malicious links.
Differentiate spear phishing from whaling.
Spear phishing targets specific individuals or groups with tailored messages; whaling specifically targets high-profile executives like CEOs or CFOs.
What is vishing and smishing?
Vishing is voice/phone-based phishing; smishing is SMS/text-message-based phishing.
See more Threats, Vulnerabilities, and Mitigations flashcards →
Planning Threats, Vulnerabilities, and Mitigations for CompTIA Security+
Threats, Vulnerabilities, and Mitigations is about 19% of the CompTIA Security+ syllabus by topic count — 22 of 117 topics, spread over 5 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 30 hours.
The heaviest chapters are Vulnerability Types (6 topics), Malicious Activity and Indicators (5 topics), Threat Vectors and Attack Surfaces (4 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Threats, Vulnerabilities, and Mitigations (CompTIA Security+) FAQ
What is in the CompTIA Security+ Threats, Vulnerabilities, and Mitigations syllabus?
Threats, Vulnerabilities, and Mitigations is split into 5 chapters — Threat Actors and Motivations, Threat Vectors and Attack Surfaces, Vulnerability Types, Malicious Activity and Indicators and Mitigation Techniques, containing 22 topics and 60 sub-topics in total.
How many chapters are there in Threats, Vulnerabilities, and Mitigations for CompTIA Security+?
5 chapters. Threats, Vulnerabilities, and Mitigations accounts for about 19% of the topics in the whole CompTIA Security+ syllabus (22 of 117).
How long should I spend on Threats, Vulnerabilities, and Mitigations for CompTIA Security+?
Budget around 30 hours for a first pass through Threats, Vulnerabilities, and Mitigations — about 45 minutes per topic plus 12 minutes per sub-topic across its 22 topics. Add revision cycles on top.
Are there flashcards for CompTIA Security+ Threats, Vulnerabilities, and Mitigations?
Yes — a 65-card Threats, Vulnerabilities, and Mitigations deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.