Tyscorpa Study resources Open the Academy

Threat Vectors & Attack Surfaces

How attackers gain initial access — the pathways and surfaces they exploit.

SY0-701 Obj. 2.2 Threats, Vulnerabilities & Mitigations 22% of the exam

Attack Surface vs. Attack Vector

Message-Based Vectors

AttackDescriptionExample / Tip
PhishingBulk deceptive emails impersonating trusted entities"Your account is suspended — click here"
Spear PhishingTargeted phishing using personalized informationEmail to CFO referencing a real project
WhalingSpear phishing targeting senior executives (CEO, CFO)Fake legal subpoena targeting the CEO
VishingVoice phishing via phone callCaller impersonating IT support asking for password
SmishingSMS-based phishing"Your package is delayed — click link to reschedule"
PharmingRedirecting DNS so victim goes to fake site (even with correct URL)DNS poisoning to redirect bank.com to attacker server
TyposquattingRegistering misspelled domain namesgooogle.com, paypa1.com
BEC (Business Email Compromise)Impersonating executives or vendors to authorize fraudulent wire transfersCEO fraud — attacker spoofs CEO's email to CFO

Social Engineering Principles

Attackers exploit psychological weaknesses. Key principles used:

Supply Chain Attack Surface

Attackers compromise a trusted vendor/partner to gain access to the target organization.

Notable Examples:
  • SolarWinds (2020): Nation-state actors (Cozy Bear) inserted malicious code into SolarWinds Orion software updates. ~18,000 organizations installed the backdoor.
  • Target Breach (2013): Attackers compromised an HVAC vendor's credentials to gain access to Target's network.
  • Log4Shell (2021): Vulnerability in the Log4j open-source library affected millions of applications.

Countermeasures: Software Bill of Materials (SBOM), vendor assessments, code signing, integrity checks on updates.

Other Threat Vectors

Exam Tip: The exam loves scenario questions about social engineering. Key identifiers: the attack uses deception, exploits human psychology, and doesn't rely on technical exploits. Countermeasure = security awareness training.

External Resources

PreviousThreat Actors & Motivations NextMitigation Techniques

Test yourself on this

Reading is the easy half. The Academy has 1,360 exam-style questions, including performance-based ones, and it keeps pulling from whichever domain you keep getting wrong. Free to create an account.

Open the Academy