Security+ · Domain 2
Threats, Vulnerabilities and Mitigations
About 22% of the exam
Threat actors
- Nation-state
- well funded, patient, stealthy
- Unskilled attacker
- runs tools written by others
- Hacktivist
- political or philosophical message
- Insider threat
- legitimate access, knows the gaps
- Organized crime
- profit driven, ransomware and fraud
- Shadow IT
- staff deploying unapproved services
- Attributes
- internal or external, funding, sophistication
Living off the land plus months of patience points at a nation-state, not a criminal crew
Motivations
- Data exfiltration and espionage
- Financial gain and extortion
- Blackmail after data theft
- Service disruption and chaos
- Philosophical or political belief
- Revenge by a former insider
- Ethical testing with written permission
- War, directed by a state
Threat vectors
- Message based
- email, SMS, instant messaging
- Image and file
- malicious attachment or embedded payload
- Voice call
- vishing aimed at the help desk
- Removable device
- USB dropped in the car park
- Vulnerable software
- client based or agentless flaws
- Unsupported systems
- no patch will ever arrive
- Unsecure networks
- open wireless, Bluetooth, rogue cabling
- Open service ports
- listening services nobody needed
- Default credentials
- shipped password never changed
- Supply chain
- vendor, supplier or managed provider
Human vectors
- Phishing
- mass email hunting credentials
- Spear phishing
- researched, aimed at one team
- Whaling
- aimed at a senior executive
- Vishing
- phone call, urgency and authority
- Smishing
- text message carrying a link
- Business email compromise
- invoice or wire transfer fraud
- Pretexting
- invented story opens the conversation
- Watering hole
- poison a site they already visit
- Typosquatting
- domain one keystroke away
- Misinformation
- false narrative seeded deliberately
The malware zoo
Spreads by itself
- Worm needs no user action
- Virus attaches to a host file
- Fileless code runs from memory
- Polymorphic code rewrites its own signature
Hides and persists
- Trojan pretends to be useful software
- Rootkit hides at kernel level
- Logic bomb waits for a condition
- Backdoor keeps the way back in
- Bloatware ships preinstalled and unwanted
Steals or extorts
- Ransomware encrypts then demands payment
- Keylogger records every keystroke
- Spyware reports browsing and files
- Scareware fakes an infection warning
- Cryptominer quietly steals compute cycles
Modern ransomware is double extortion: data is copied out before encryption, so a clean restore does not end the breach
Attack techniques by layer
Network
- DDoS, amplified or reflected
- On-path intercepts the conversation
- DNS poisoning and domain hijacking
- ARP poisoning on the local segment
- Credential replay of captured traffic
Application
- SQL injection through unvalidated input
- Cross-site scripting runs in the browser
- Buffer overflow overwrites adjacent memory
- Directory traversal escapes the web root
- Request forgery rides the victim session
- Race condition between check and use
Cryptographic
- Downgrade forces a weaker protocol
- Collision, two inputs one hash
- Birthday attack on short hashes
- Harvest now, decrypt later
Input validation on the server side kills injection, scripting and traversal; client side checks are advisory only
Vulnerability classes
- Application
- memory injection, overflow, race conditions
- Web based
- injection and cross-site scripting
- Operating system
- unpatched kernel and service flaws
- Hardware
- firmware, end of life, legacy
- Virtualization
- VM escape and resource reuse
- Cloud specific
- misconfigured storage and identity
- Supply chain
- vendor, supplier, service provider
- Cryptographic
- weak cipher, reused key, poor randomness
- Mobile
- side loading and jailbreaking
- Zero-day
- no patch exists yet
Indicators of malicious activity
- Account lockout with no user error
- Concurrent sessions in two places
- Impossible travel between two logins
- Security tooling blocked or tampered with
- Resource consumption spikes with no cause
- Resources suddenly inaccessible to everyone
- Out of cycle logging overnight
- Missing logs where logs belong
- Attacker publishes the stolen data
Beaconing at a fixed interval to one external address is command and control until proven otherwise
Password and credential attacks
- Password spraying
- one password, many accounts
- Brute force
- many passwords, one account
- Credential stuffing
- breached pairs replayed elsewhere
- Dictionary attack
- wordlist plus common mutations
- Rainbow table
- precomputed hashes, salt defeats it
- Pass the hash
- reuse the hash, skip cracking
- MFA fatigue
- prompt spam until someone approves
- Session hijack
- steal the cookie, skip login
Hardening the endpoint
- Remove unnecessary software and services
- Change default passwords everywhere
- Close ports and disable legacy protocols
- Host firewall and host intrusion prevention
- EDR agent with tamper protection
- Encrypt the disk on portable devices
- Apply the vendor security baseline
- Enforce configuration and detect drift
- Decommission systems nobody owns
Mitigation techniques
- Segmentation
- limits lateral movement between zones
- Isolation
- cut the host off completely
- Access control
- permissions and access control lists
- Application allow list
- only approved binaries execute
- Patching
- closes the known vulnerability
- Encryption
- protects data that leaks anyway
- Monitoring
- catches what prevention missed
- Least privilege
- fewer rights, smaller blast radius
Wireless and physical attacks
- Evil twin
- rogue radio using the same SSID
- Rogue access point
- unauthorized radio on your network
- Deauthentication
- forged frames knock clients off
- Jamming
- radio noise denies service
- RFID cloning
- badge copied at a distance
- Brute force entry
- forcing the door or cabinet
- Environmental
- heat, water or power attack
First and best actions
- Confirm the alert is real
- Contain the affected host
- Preserve volatile evidence
- Eradicate the root cause
- Recover and monitor
- Lessons learned
- Isolate before you rebuild
- Capture memory before powering down
- Reset every credential the attacker touched
- Patch the flaw that allowed entry
FIRST questions want the spread stopped; BEST questions want the cause removed
Rapid recall
- Threat
- the actor or the event
- Vulnerability
- the weakness they exploit
- Exploit
- the code or method used
- Attack surface
- everything an attacker can reach
- Lateral movement
- hopping host to host
- Persistence
- surviving reboot and cleanup
- Exfiltration
- data leaving the estate
- Dwell time
- entry until detection
Reference strip: actors, attacks, indicators, mitigations
Actors and vectors
- Nation-state, crime, hacktivist, insider
- Unskilled attacker, shadow IT
- Message, image, file, voice, removable media
- Supply chain and managed service provider
Social engineering
- Phishing, spear phishing, whaling
- Vishing, smishing, pretexting
- Business email compromise, impersonation
- Watering hole, typosquatting, brand abuse
- Misinformation and disinformation
Malware to name
- Virus, worm, trojan, rootkit
- Ransomware, keylogger, spyware, bloatware
- Logic bomb, backdoor, cryptominer
- Fileless and polymorphic variants
Indicators
- Impossible travel, concurrent sessions
- Account lockout, blocked content
- Resource spikes, missing logs
- Out of cycle logging, beaconing
Mitigations
- Segmentation, isolation, least privilege
- Patching and configuration enforcement
- Application allow list, host firewall
- Encryption, monitoring, decommissioning
Quick exam traps
- Trap: A virus and a worm spread in the same way
- Trap: Signature antivirus reliably catches fileless malware
- Trap: Paying the ransom ends the data breach
- Trap: Password spraying and brute force are the same attack
- Trap: Salting stops an attacker guessing a weak password
- Trap: Powering the machine off is the right first response
- Trap: An insider threat is always deliberate and malicious
- Trap: A zero-day stops being a zero-day once it is exploited
cybercertprep.com · original revision sheet written from the public body of knowledge