CFS136 · Principles of Information Security

Chapter 3 Review: Threat Vectors and Attack Surfaces

A hands-on review station for message-based, browser, network, endpoint, supply chain, wireless, and human attack vectors from Chapter 3.

Start Here

Six review stations, each a different way to practice Chapter 3. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or the exam.

What this chapter asked you to be able to do

  • Identify message-based vectors: phishing, spear-phishing, whaling, Business Email Compromise (BEC), vishing, and smishing.
  • Analyze image, attachment, and browser vectors, including malicious QR codes, Office macros, drive-by downloads, and cross-site scripting.
  • Explain network and remote access vectors, including DNS hijacking, RDP exposure, and VPN credential compromise.
  • Assess endpoint, supply chain, wireless, and physical vectors that expand the attack surface beyond the network boundary.
  • Categorize application and credential vulnerabilities and prioritize mitigation by likelihood and impact.
Two words to keep straight An attack surface is the total set of assets and entry points exposed to attack. An attack vector is the specific path an attacker takes to reach one of them. Reducing exposure means shrinking the surface and closing individual vectors.

Your progress this session

These counters update as you check answers on each station. They reset when you reload the page.

0/20Terms viewed
0/10Vector matches correct
0/6Social techniques correct
0/8App attacks correct
0/10Quiz correct
How to use each station Make a choice, then select Check to see whether it holds up and why. Every answer includes the reasoning, so a wrong pick is a chance to reread the logic rather than just the label. Keyboard users can move between tabs with the arrow keys.