Threat vectors: messages, attachments, networks, remote access and the supply chain

This course teaches SY0-801, the Security+ exam that launches on or around 17 November 2026. If you are booked on SY0-701, which can be taken until 11 June 2027, use our SY0-701 course instead.

Listen to this lesson

Episode 11 · 53:30

Every episode of this course is also a podcast: listen on Spotify.

This episode is a study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.

Objective 2.3 · Threats, Vulnerabilities, and Attacks · 24% of the exam

Objective 2.3 asks you to describe threat vectors — the routes by which an attack reaches its target. SY0-801 roughly doubled the list. This lesson takes the routes that arrive over a wire: messages, images and attachments, network infrastructure, remote access, the supply chain and removable media. The next lesson takes browsers, endpoints, people, devices, physical access and radio.

Why this matters

A vector is the route; a technique is what is done once the route is open. The exam keeps them apart, and so should you: "a phishing email delivered ransomware" involves a vector from this objective, a social engineering technique from 2.5 and a malware type from 2.5, and a question will ask about exactly one of them.

Several vectors here need nobody to be fooled at all. An exposed remote desktop service, an unpatched VPN gateway or a compromised update from a trusted supplier works without a user making any mistake, which means awareness training does nothing about it. Knowing which vectors are human and which are not is half of choosing the right control.

The lesson

Email, text, RCS, chat and collaboration tools as delivery channels

Message-based vectors deliver content straight to a person. Each channel has its own weaknesses:

  • Email remains the largest. It carries links, attachments and convincing impersonation, and it is the channel with the most mature defences — gateway filtering, sandboxing and sender authentication — so attackers increasingly move elsewhere.
  • SMS reaches a phone, where links are truncated, messages are read in seconds, and texts borrow legitimacy from genuine bank and delivery alerts.
  • RCS (Rich Communication Services) is the richer successor to SMS: media, read receipts, branded business senders, carried over data. It largely sidesteps the filtering mobile carriers built for SMS, and phishing services have been reported using it for exactly that reason.
  • Instant messaging apps are personal, trusted and usually outside corporate monitoring.
  • Collaboration tools — workplace chat, shared channels, file-sharing platforms — are trusted because they are internal. A message that appears in the company chat feels like it came from a colleague. Attackers have posed as the help desk from external accounts in exactly these tools, and a shared document link from a real partner's compromised account passes every reputation check.

The controls follow the channel: gateway filtering and sender authentication for email; restricting who outside the organisation can message staff in collaboration tools and labelling external senders clearly; mobile threat defence on managed phones; and a reporting route users can reach from every channel, not just email. The social engineering carried over these channels — phishing, smishing and the rest — is covered in the social engineering lesson.

QR codes, embedded content and booby-trapped documents: macros, RTF and PDF

Image-based vectors hide the dangerous part inside a picture.

  • A QR code is a link nobody can read. A filter that scans URLs in text sees only an image, and the code is usually opened on a personal phone outside corporate protection. Codes stuck over genuine ones on parking meters and posters are the physical version.
  • Embedded content — images or frames that load from a remote server — can confirm that a message was opened, reveal the reader's address and device, or pull in content the filter never inspected.
  • CAPTCHA pages are used in two ways. Phishing sites put one in front of the real page so automated scanners never reach it. And fake "verify you are human" pages instruct the user to press a sequence of keys that pastes and runs a command — a trick that turns the user into the installer.

Attachment-based vectors carry the payload in a file:

  • Embedded macros in office documents run code when enabled. Office products now block macros in files from the internet by default, which is why attackers moved to other formats.
  • RTF documents can embed objects that are processed when the file opens, and have repeatedly been used to reach flaws in the software that renders them.
  • PDFs can contain scripts, embedded files and links, and their trusted look makes the link inside one more credible.

Controls: block risky file types at the gateway; keep macros disabled by policy for files from outside; preserve the mark that tags downloaded files so protected viewing applies; detonate attachments in a sandbox; strip active content with content disarm and reconstruction; and train users that a page asking them to paste something into a run box is never a real check.

Infrastructure and virtualised network devices, and stolen session keys

Network-based vectors target the equipment that carries traffic rather than the people using it.

Infrastructure devices — routers, switches, firewalls, VPN gateways, load balancers — are attractive because they sit at the edge, see everything that passes, rarely run endpoint protection, are patched less often than servers, and are often managed through an interface reachable from more places than it should be. A compromised edge device gives an attacker a vantage point that most monitoring does not cover. Controls: patch them as urgently as servers, keep management interfaces on a separate management network, log their activity to a SIEM, and inventory them so none is forgotten.

Virtualised devices — virtual switches, virtual firewalls, software-defined appliances — carry the same risks plus a new one: whoever controls the virtualisation platform controls the network. A hypervisor management console is therefore a network control point and needs protecting like one.

Session keys are the short-lived keys that encrypt one connection after the handshake. If an attacker obtains them — from a compromised endpoint's memory, or from a device that terminates encryption — they can read or hijack that session without ever touching a password. Forward secrecy limits the damage of a stolen long-term key, because each session's key is derived fresh and cannot be recomputed later; protecting devices that decrypt traffic limits the rest.

Remote desktop, VNC and VPN as the doors attackers try first

Remote access vectors are popular because they lead straight to an interactive session inside the network.

  • Remote desktop exposed directly to the internet is one of the most common initial access routes for ransomware. It is found by constant automated scanning and attacked with guessed and stolen credentials.
  • VNC tools are widespread in support and industrial settings, and are often deployed with weak authentication, without encryption, or with no password at all.
  • VPN gateways are the opposite problem: meant to be exposed, so a flaw in one is reachable by everyone. VPN appliance vulnerabilities have been among the most exploited in recent years, and a VPN account without MFA turns a stolen password into network access.

The controls are consistent: never expose remote desktop or VNC directly — put them behind a gateway or VPN; require MFA on every remote access path; patch VPN appliances within days of an advisory, not weeks; restrict by source where possible; and alert on remote logins at unusual times or from unusual places.

Third parties, MSPs, logistics and SaaS providers, and the malicious USB stick

Supply chain vectors compromise you through someone you trust:

  • Third-party providers — any supplier with access to your systems, data or premises. Their weakest control becomes yours.
  • Managed service providers (MSPs) hold privileged remote access to many clients at once. Compromising one MSP reaches every client, which makes them the highest-leverage target in the category.
  • Logistics providers move your hardware and goods. Equipment can be tampered with in transit, and the logistics firm's own systems and portals connect to yours.
  • SaaS providers hold your data and are connected to your identity provider and other applications. A breach at the provider, or a stolen integration token, exposes your data without any attack on your network.

The pattern that makes these hard is that every conventional control says yes. The software update is correctly signed. The traffic comes from an allowed supplier address. The MSP's account is supposed to have admin. The answers are contractual and structural: assess suppliers before and during the relationship, give third parties only the access they need and only when they need it, monitor what they do rather than only whether they are authorised, stage updates so a small group takes them first, and keep a software bill of materials so you can answer "are we affected?" quickly. Domain 5 covers the assessment side.

External media closes the list. A malicious USB device left in a car park or posted to an employee still works, for two reasons: curiosity, and the fact that a device can present itself as something other than storage. A "USB drive" can identify itself as a keyboard and type commands the moment it is plugged in, defeating any control aimed at files. The controls are disabling autorun, blocking unapproved removable storage, allowing only approved encrypted devices, and device control that blocks unrecognised input devices.

What to take into the exam

  • Vector is the route; technique is what is done with it. A question usually gives you one and asks for the other.
  • QR codes and images carry links past text-based filters; fake CAPTCHA pages turn the user into the installer.
  • Macros, RTF and PDF are the named attachment vectors; sandboxing, macro policy and content disarm answer them.
  • Edge infrastructure is a prime target because it sees everything and runs no endpoint agent.
  • Never expose RDP or VNC directly; put MFA on every remote access path and patch VPN gateways fast.
  • Supply chain attacks pass every conventional control; MSPs are high leverage because one breach reaches every client.
  • A malicious USB may act as a keyboard, so file-level controls miss it.

Practise what you just read

1. Which of these threat vectors works without any user making a mistake, so that awareness training does nothing to close it?

Select one

  1. A QR code in an email asking staff to re-register
  2. A fake CAPTCHA asking visitors to paste a command
  3. An unpatched VPN gateway reachable from the internet
  4. A macro-enabled document sent from a supplier's mailbox
Show answer

C. An exposed, unpatched VPN appliance can be exploited by anyone who reaches it, with no user involved, so patching within days of an advisory and MFA are the answers. The QR code, fake CAPTCHA and macro document all depend on a person scanning, pasting or enabling something.

2. Which supply chain relationship gives an attacker the greatest leverage from a single compromise?

Select one

  1. A logistics firm that ships your hardware
  2. A SaaS provider hosting one business tool
  3. A hardware vendor that supplies your switches
  4. An MSP with admin access to many clients
Show answer

D. A managed service provider holds privileged remote access to many clients at once, so compromising one MSP reaches every client. The other relationships are real supply chain risks, but each exposes one customer relationship rather than an entire client base through a single set of credentials.

3. Why do supply chain attacks such as a hostile vendor update pass most conventional controls?

Select one

  1. Every control approves the signature and source
  2. They arrive over unencrypted channels tools ignore
  3. Signature checking is normally disabled to save time
  4. Endpoint agents are paused while updates install
Show answer

A. The update is correctly signed, the traffic comes from an allowed supplier and the supplier's account is supposed to have access. The answers are therefore structural: assess suppliers, give third parties only the access they need, stage updates so a small group takes them first, and monitor what they do.

Hands-on labs

All hands-on labs

This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.