🇺🇸 CompTIA Security+ · flashcards

CompTIA Security+ Threats, Vulnerabilities, and Mitigations Flashcards

65 question-and-answer cards covering Threats, Vulnerabilities, and Mitigations as it is examined in CompTIA Security+. 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

65Cards in deck
24Free preview
22Syllabus topics
~132Chars per answer
FreePrice

24 sample cards from the Threats, Vulnerabilities, and Mitigations deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. Differentiate a virus from a worm.

    A virus requires a host file and user action to spread; a worm is self-replicating and spreads across networks automatically without user interaction.

  2. What is a Trojan horse?

    Malware disguised as legitimate software that performs hidden malicious actions once installed by the user.

  3. What is a rootkit and what makes it dangerous?

    Malware that gains privileged (root) access and hides its presence, often operating at the kernel level to evade detection.

  4. What is ransomware?

    Malware that encrypts a victim's data or locks systems, demanding payment (ransom) for restoration or to prevent data leakage.

  5. What is a keylogger?

    Software or hardware that records a user's keystrokes to capture passwords, messages, and other sensitive input.

  6. What is a distributed denial-of-service (DDoS) attack?

    Overwhelming a target system or network with traffic from many compromised sources (a botnet) to make it unavailable to legitimate users.

  7. What is an on-path (man-in-the-middle) attack?

    An attacker secretly intercepts and possibly alters communication between two parties who believe they are communicating directly.

  8. Differentiate a brute-force attack from a dictionary attack.

    A brute-force attack tries every possible character combination; a dictionary attack uses a precompiled list of likely passwords/words.

  9. What is a birthday attack?

    A cryptographic attack exploiting the probability math behind hash collisions, finding two inputs that produce the same hash output.

  10. What is salting and how does it defend against password attacks?

    Adding random data to a password before hashing so identical passwords yield different hashes, defeating precomputed rainbow tables.

  11. What is a rainbow table attack?

    Using precomputed tables of hash values to quickly reverse password hashes back to plaintext; mitigated by salting.

  12. What are Indicators of Compromise (IoCs)?

    Forensic evidence that a breach has occurred, such as unusual outbound traffic, account lockouts, impossible travel logins, malicious file hashes, or unexpected changes.

  13. Give examples of common Indicators of Compromise.

    Account lockouts, concurrent/impossible-travel session usage, blocked content, resource consumption spikes, missing logs, published/leaked data, and unusual outbound traffic.

  14. What is network segmentation and how does it mitigate threats?

    Dividing a network into isolated zones (e.g., via VLANs) to limit lateral movement and contain breaches within a segment.

  15. What is the principle of least privilege?

    Granting users and processes only the minimum access rights necessary to perform their function, reducing the attack surface.

  16. What is application allow listing (whitelisting)?

    A security control that permits only explicitly approved applications to run, blocking all others by default.

  17. Compare application allow listing with deny listing (blocklisting).

    Allow listing blocks everything except approved apps (default-deny, more secure); deny listing allows everything except known-bad apps (default-allow, less secure).

  18. What is application sandboxing/isolation?

    Running an application in a restricted, isolated environment so it cannot affect other processes or the host system if compromised.

  19. What are common system hardening targets?

    Servers, workstations, mobile devices, network appliances (switches/routers), cloud infrastructure, IoT/embedded devices, and ICS/SCADA systems.

  20. What does system hardening involve?

    Reducing the attack surface by disabling unnecessary services/ports, removing default accounts, applying patches, configuring secure settings, and enforcing least privilege.

  21. What is the role of patch management in hardening?

    Regularly applying vendor updates to fix known vulnerabilities before attackers can exploit them.

  22. What is host-based endpoint protection used in hardening?

    Software like host-based firewalls, HIDS/HIPS, antivirus/EDR, and disk encryption that protects individual devices from threats.

  23. What is the purpose of disabling unused ports and services during hardening?

    It removes potential entry points, shrinking the attack surface available to threat actors.

  24. What is a default credential vulnerability and how is it mitigated?

    Using factory-set usernames/passwords that attackers know; mitigated by changing all default credentials immediately upon deployment.

What this deck covers

The Threats, Vulnerabilities, and Mitigations deck follows the CompTIA Security+ Threats, Vulnerabilities, and Mitigations syllabus — 5 chapters and 22 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 13.0 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 132 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Threats, Vulnerabilities, and Mitigations flashcards FAQ

How many Threats, Vulnerabilities, and Mitigations flashcards are in this CompTIA Security+ deck?

65 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these CompTIA Security+ flashcards free?

Yes. The preview here is free to read with no signup, and the full 65-card deck is free inside the Examius app.

What do the Threats, Vulnerabilities, and Mitigations cards cover?

They follow the CompTIA Security+ Threats, Vulnerabilities, and Mitigations syllabus — 5 chapters and 22 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.