Vulnerabilities and Malicious Activity Indicators
This topic covers application, network, cloud, mobile, and operational vulnerabilities plus malware behavior and indicators of compromise.
How to study for Security+
Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.
Core concepts
Concept 1
A vulnerability is a weakness; exploitation depends on threat capability, exposure, and control failure.
Exam cue: Identify weakness, exploit path, and observable indicator separately.
Concept 2
Malicious activity indicators include unusual processes, network traffic, authentication events, files, registry changes, and user behavior.
Exam cue: Use symptoms to distinguish malware, credential, web, and network attacks.
Concept 3
Application attacks often exploit input handling, authentication, session management, insecure design, or misconfiguration.
Exam cue: Treat misconfiguration as a security vulnerability.
Risk pitfalls and guardrails
Calling every alert malware without checking evidence.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Ignoring cloud identity or storage misconfiguration.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Fixing symptoms without closing the exploited weakness.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Memory anchors
Vulnerability
A vulnerability is a weakness that can be exploited to reduce confidentiality, integrity, or availability.
Exploit
An exploit is code, technique, or action that takes advantage of a vulnerability.
IOC
An indicator of compromise is observable evidence that malicious activity may have occurred.
Malware
Malware is software designed to harm, disrupt, steal, spy, extort, or gain unauthorized access.
Ransomware
Ransomware denies access to data or systems and demands payment for recovery or non-disclosure.
SQL Injection
SQL injection sends untrusted input that changes database queries or exposes data.
XSS
Cross-site scripting injects script into trusted web content viewed by other users.
CSRF
Cross-site request forgery tricks an authenticated browser into submitting an unwanted request.
Privilege Escalation
Privilege escalation gains access rights beyond the original authorization level.
Misconfiguration
Misconfiguration exposes risk through insecure defaults, excessive permissions, open services, or weak settings.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A web server runs a library version with a published remote-code-execution flaw, but no attack has been observed. What does the flaw represent?
A researcher sends a specially crafted request that takes advantage of a known parser flaw and opens a shell. What is the request functioning as?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
