Topic module

Vulnerabilities and Malicious Activity Indicators

This topic covers application, network, cloud, mobile, and operational vulnerabilities plus malware behavior and indicators of compromise.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for Security+

Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.

Core concepts

Concept 1

A vulnerability is a weakness; exploitation depends on threat capability, exposure, and control failure.

Exam cue: Identify weakness, exploit path, and observable indicator separately.

Concept 2

Malicious activity indicators include unusual processes, network traffic, authentication events, files, registry changes, and user behavior.

Exam cue: Use symptoms to distinguish malware, credential, web, and network attacks.

Concept 3

Application attacks often exploit input handling, authentication, session management, insecure design, or misconfiguration.

Exam cue: Treat misconfiguration as a security vulnerability.

Risk pitfalls and guardrails

Calling every alert malware without checking evidence.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Ignoring cloud identity or storage misconfiguration.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Fixing symptoms without closing the exploited weakness.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Memory anchors

Vulnerability

A vulnerability is a weakness that can be exploited to reduce confidentiality, integrity, or availability.

Exploit

An exploit is code, technique, or action that takes advantage of a vulnerability.

IOC

An indicator of compromise is observable evidence that malicious activity may have occurred.

Malware

Malware is software designed to harm, disrupt, steal, spy, extort, or gain unauthorized access.

Ransomware

Ransomware denies access to data or systems and demands payment for recovery or non-disclosure.

SQL Injection

SQL injection sends untrusted input that changes database queries or exposes data.

XSS

Cross-site scripting injects script into trusted web content viewed by other users.

CSRF

Cross-site request forgery tricks an authenticated browser into submitting an unwanted request.

Privilege Escalation

Privilege escalation gains access rights beyond the original authorization level.

Misconfiguration

Misconfiguration exposes risk through insecure defaults, excessive permissions, open services, or weak settings.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A web server runs a library version with a published remote-code-execution flaw, but no attack has been observed. What does the flaw represent?

A researcher sends a specially crafted request that takes advantage of a known parser flaw and opens a shell. What is the request functioning as?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.