Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 48 pages
Exam (elaborations)

WGU C795 (CompTIA Security+ SY0-701): ULTIMATE Context-Driven Study Guide - Performance-Based Scenarios & Exam Blueprint Mastery

Document preview thumbnail
Preview 4 out of 48 pages

Accelerate your WGU C795 course completion and PASS the CompTIA Security+ (SY0-701) exam with this ULTIMATE Context-Driven Study Guide. Specifically designed for the WGU assessment structure, this comprehensive guide moves beyond memorization to teach you how to apply security concepts to real-world, performance-based scenarios. It breaks down the entire SY0-701 exam blueprint into digestible modules focused on threats, attacks, and vulnerabilities; architecture and design; implementation; operations and incident response; and governance, risk, and compliance. Each module integrates hands-on exercises, PBQ (Performance-Based Question) walkthroughs, and contextual explanations that link theory to practical implementation. Master the exact skills needed for both the WGU objective assessment and the CompTIA certification. This is the definitive resource for competency-based learning, ensuring you not only know the material but can execute it.

Content preview

WGU C795 (CompTIA Security+ SY0-701):
ULTIMATE Context-Driven Study Guide -
Performance-Based Scenarios & Exam Blueprint
Mastery



DOMAIN 1: THREATS, ATTACKS, AND VULNERABILITIES

Focus: Identifying Attack Patterns, Malware Behaviors, and Indicators of Compromise



Scenario Q1:

A security analyst reviewing SIEM logs notices multiple failed login attempts from a
foreign IP against the VPN gateway, followed 20 minutes later by a successful login
from the internal HR department's IP range. The HR user account shows no recent
password change activity. What type of attack is MOST likely occurring?

A) Credential stuffing

B) Pass-the-hash

C) Password spraying

D) Brute force

Correct Answer: B

Complete Solution:

,Step 1: Context Breakdown

●​ Role: Security Analyst (monitoring/detection function)
●​ Threat Pattern: External reconnaissance (failed foreign logins) → lateral
movement via internal HR IP
●​ Key Anomaly: Successful internal login without password change after external
targeting
●​ Action Keyword: "MOST likely" — requires matching attack pattern to observed
indicators

Step 2: Concept Reinforcement
This describes lateral movement using compromised credentials without knowing the
plaintext password. Pass-the-hash attacks use NTLM hash values stolen from one
system to authenticate to others, leaving no password change trail.

Step 3: Why Right & Why Wrong

TableCopy


Answer Analysis



External reconnaissance followed by internal lateral movement without
B) Pass-the-hash ✓ password change = hash replay. The HR IP suggests the attacker
pivoted to an internal system.



Uses breached username/password pairs from other sites. Would
A) Credential stuffing show successful external login, not failed external then successful
internal.



Uses common passwords against many accounts. Would show
C) Password spraying multiple accounts targeted, not one account with lateral movement
pattern.

, Attempts all possible passwords. Would take far longer and generate
D) Brute force massive log volume; unlikely to succeed in 20 minutes against a VPN
gateway.


Step 4: Exam Relevance
Tests Objective 1.2: Compare and contrast types of attacks, specifically
credential-based attacks and lateral movement techniques.

ProTip: When you see "successful login without password change" after external
activity, immediately consider hash-based attacks or Kerberoasting. The absence of
password change is the critical differentiator.



Scenario Q2:

Following a malware outbreak, your incident response team isolates infected
workstations. Forensic analysis reveals a fileless malware that resides only in memory,
establishes a reverse shell to a C2 server, and uses PowerShell to enumerate domain
users. Which MITRE ATT&CK tactic BEST describes the PowerShell activity?

A) Initial Access

B) Execution

C) Discovery

D) Collection

Correct Answer: C

Complete Solution:

Step 1: Context Breakdown

, ●​ Role: Incident Responder (forensic analysis phase)
●​ Attack Stage: Post-exploitation (fileless malware active, C2 established)
●​ Specific Activity: PowerShell used to "enumerate domain users"
●​ Action Keyword: "BEST describes" — requires precise MITRE tactic mapping

Step 2: Concept Reinforcement
MITRE ATT&CK tactics represent the "why" of an attack technique. Discovery (TA0007)
involves techniques that allow adversaries to gain knowledge about the system and
internal network—specifically including account and permission enumeration.

Step 3: Why Right & Why Wrong

TableCopy


Answer Analysis



Enumerating domain users is classic reconnaissance to understand the
C) Discovery ✓
environment for privilege escalation or lateral movement targets.



A) Initial Access Already completed—malware is resident and C2 is established.



PowerShell is the execution method, but the purpose of this specific activity
B) Execution is discovery. The question asks what the activity describes, not what tool is
used.



Involves gathering data of interest (files, credentials). Enumeration is
D) Collection
reconnaissance, not data collection.


Step 4: Exam Relevance
Tests Objective 1.7: Explain the techniques used in penetration testing, including MITRE
ATT&CK framework application.

Document information

Uploaded on
February 10, 2026
Number of pages
48
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$13.00

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
PrimeScholars
3.2
(13)
Sold
85
Followers
0
Items
3160
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions