Section 2: 35–45%I8
Threats, Vulnerabilities, and Attacks
Exam insight
The exam expects you to name attack types precisely and to keep straight the difference between a threat, a vulnerability, and a risk. Recognizing whether a scenario describes phishing, ransomware, SQL injection, or an insider threat drives both the correct answer and the right control recommendation.
What AICPA wants you to know
- 1Distinguish a threat from a vulnerability and from risk.
- 2Identify the major malware types and how they differ.
- 3Recognize social engineering, phishing, and spear phishing.
- 4Explain denial-of-service, SQL injection, man-in-the-middle, and zero-day attacks.
- 5Describe the nature and indicators of insider threats.
- 6Contrast vulnerability scanning with penetration testing.
Patterns in this topic
The exam re-skins the same archetypes. Recognize these here, then drill them in the Pattern Lab.
Exam tip
Study smarter: before you expand each card, cover the screen and try to recall what the concept means from its title alone. Retrieving it from memory builds the recall the exam actually tests, and it beats re-reading.