Preparing for the CompTIA Security+ SY0-701 certification exam requires understanding how attackers gain access to systems through different threat vectors. Some of the most important examples involve unsupported systems and applications, vulnerable wireless technologies, physical network connections, and Bluetooth attacks.
Unsupported Systems and Applications
Systems and applications that are no longer supported by their manufacturer are especially vulnerable to attacks involving known vulnerabilities.
An unsupported operating system or application may contain a security flaw that has already been publicly documented. The problem is that the vendor may no longer release security patches for the product.
This creates an important Security+ relationship:
Known vulnerability → Unsupported system or application
A legacy system may also be old and vulnerable, but “legacy” does not automatically mean “unsupported.” A legacy system could still receive security updates. When a question specifically emphasizes exploitation of a known vulnerability, unsupported software is especially important because known flaws may remain permanently unpatched.
Search concepts associated with this topic include unsupported operating systems, end-of-life software, unpatched vulnerabilities, legacy applications, vulnerability management, patch management, cybersecurity threat vectors, and Security+ SY0-701 vulnerabilities.
Wireless Technologies as Threat Vectors
Wireless technologies can introduce security weaknesses when they rely on vulnerable standards or configuration methods.
Important technologies to recognize include:
WEP is an obsolete wireless encryption standard with serious security weaknesses.
WPA improved on WEP but is also considered outdated and should generally be replaced by stronger standards.
WPS, or Wi-Fi Protected Setup, was designed to make connecting devices easier. Certain implementations, particularly PIN-based WPS, are vulnerable to attacks.
For this practice-test question, WPA2 is also included among the wireless technologies considered potential threat vectors due to known vulnerabilities.
The answer set to remember from this question is:
WPS + WPA + WPA2 + WEP
This does not mean these technologies all have identical weaknesses. It means the practice-test question groups them as wireless technologies associated with known security vulnerabilities.
Cable Tapping
When a Security+ question asks for a threat vector that is characteristic specifically of a wired network, think about the physical cable.
Cable tapping involves gaining access to network communications by physically tapping into a wired connection.
That makes the memory association:
Wired network → Cable tapping
Other attacks such as ARP spoofing can occur on networks without being defined specifically by the presence of a physical cable.
Bluetooth Threats
Bluetooth has several attacks with similar names that are useful to memorize together:
Bluesmacking involves overwhelming a Bluetooth device with traffic and can cause a denial-of-service condition.
Bluejacking involves sending unsolicited messages or data to a Bluetooth device.
Bluesnarfing involves unauthorized access to information stored on a Bluetooth device.
Bluebugging involves gaining unauthorized control over a Bluetooth device.
A simple way to separate them is:
Bluesmacking → overwhelm
Bluejacking → send
Bluesnarfing → steal
Bluebugging → control
Understanding unsupported software, wireless vulnerabilities, cable tapping, and Bluetooth attacks helps build the threat-vector knowledge needed for the CompTIA Security+ SY0-701 certification exam in 2026.
Leave a comment