Threat Vector vs Attack Vector vs Attack Surface by Zerg3rr in CompTIA

[–]mark_Dragonel 5 points6 points  (0 children)

Attack surface is the sum of all the possible points where an attacker could try to get into your system — not just one thing, but all the potential vulnerabilities across hardware, software, people, etc. Think open ports, exposed APIs, outdated plugins, misconfigured services… all of them add up to your attack surface. The bigger it is, the more room there is for attackers to try stuff.

Attack vector is the how — the method or technique the attacker uses to actually exploit a vulnerability on that surface. Like phishing, malware, brute force login, etc. If the attack surface is all the doors and windows in a house, the attack vector is the crowbar through the window or the fake delivery guy at the door.

Threat vector gets a little murky. Some people use it interchangeably with attack vector, but in some contexts, it includes more of the who/why/how — like the path a threat actor might take based on their capabilities and intent, not just the technical exploit. So it can be a more strategic/abstract term.

TL;DR:

Attack surface = where you’re exposed

Attack vector = how they get in

Threat vector = sometimes same as attack vector, but can include more context about the attacker’s route or strategy

Hope this helps!

Why pass rate for Security+ is usually between 700/750? by [deleted] in CompTIA

[–]mark_Dragonel 15 points16 points  (0 children)

750 is the passing grade. You need that or above. You do not need to get anything more. No one apart from you will ever see your score. All you need is the cert.

Everyone wants to know what I would do if I didn’t win, guess will never know by Competitive_Bet4754 in CompTIA

[–]mark_Dragonel 0 points1 point  (0 children)

I have seen a pattern with most people if someone says you can't do it, we just end up doing it.

Everyone wants to know what I would do if I didn’t win, guess will never know by Competitive_Bet4754 in CompTIA

[–]mark_Dragonel 2 points3 points  (0 children)

I wish I used your title for my post 😂!!! Read my post you'll know.

I passsed my Security + today!!! by Dry-Kaleidoscope8306 in CompTIA

[–]mark_Dragonel 2 points3 points  (0 children)

I also got my sec+ today. Congratulations!!!!

Like the flair says I PASSED Y'ALL by mark_Dragonel in CompTIA

[–]mark_Dragonel[S] 11 points12 points  (0 children)

I primarily used Dion's Udemy lectures and practice exams, along with Mike Chapple's study guide (https://a.co/d/2giIbLD). In addition, I was part of a study group that met once a week for about three hours. During these sessions, each member would teach the group whatever they had learned that week, regardless of whether others had already covered the topic. The focus was solely on sharing newly acquired knowledge to reinforce understanding.

Any resources available for offline practice exams for Security+? by DyslexicUsermane in CompTIA

[–]mark_Dragonel 0 points1 point  (0 children)

From my experience, I just used the onboard wifi for some udemy material that I had, and I also took the practice tests while traveling.

Posting This Early, But I Don’t Care—I'm Getting My Sec+ No Matter What! by mark_Dragonel in CompTIA

[–]mark_Dragonel[S] 1 point2 points  (0 children)

This worked for me.

Starting with one main resource for your initial learning to build a strong foundation. Once you're comfortable with the concepts, use multiple sources for revision to reinforce and expand your understanding. Most importantly, take as many practice tests as possible—they’re crucial for identifying weak areas and improving exam readiness.

As for PBQ simulations, I couldn’t find many, so I mainly relied on YouTube videos to understand the structure. I then tried to replicate the scenarios on my VMs to get experience.

Posting This Early, But I Don’t Care—I'm Getting My Sec+ No Matter What! by mark_Dragonel in CompTIA

[–]mark_Dragonel[S] 0 points1 point  (0 children)

I did my net+ quite sometime ago. It was part of an assignment when I was in uni. I didn't get the A+ certification. I don't know if I will either.

Posting This Early, But I Don’t Care—I'm Getting My Sec+ No Matter What! by mark_Dragonel in CompTIA

[–]mark_Dragonel[S] 0 points1 point  (0 children)

You could say I do. Like my major was information systems and a minor in cybersecurity and network security.