Security+ Domain 2

Security+ Domain 2 practice for threats and vulnerabilities

Domain 2 focuses on threats, vulnerabilities, and mitigations. Practise threat actors, malware, social engineering, vulnerability types, and the controls that reduce risk.

Threat actors

Recognise motives, capabilities, insider threats, nation-state activity, and organised crime clues.

Attacks and malware

Compare phishing, credential attacks, injection, ransomware, spyware, worms, trojans, and botnets.

Mitigations

Choose patching, hardening, segmentation, allow lists, secure configuration, and user training.

Domain 2 study goal

Practise by identifying the threat, the weakness it uses, and the mitigation that best reduces the risk.

Start SecurePlus practice

Sample Security+ Domain 2 question

Question: An attacker sends a fake delivery message that tricks a user into entering credentials. Which attack category is most relevant?

A. Phishing
B. Load balancing
C. Hashing
D. Tokenization

Answer: A. Phishing

SY0-701 Domain 2 covers threats, vulnerabilities, and mitigations, including social engineering and malware scenarios.

Quick FAQ

Is Security+ Domain 2 Practice Questions based on real exam dumps?

No. SecurePlus uses original scenario-based practice. Not exam dumps. It is an independent Security+ study tool and is not affiliated with or endorsed by CompTIA.

How should I use this Security+ Domain 2 Practice Questions page?

Use it to review Domain 2 topics, then practise that domain in SecurePlus until weak areas become clearer.