Lesson 2: Malware and Application Attacks
Week of Tue, Sep 22 · lesson closes Mon, Sep 28
Take Meerk's quiz for Lesson 2
This lesson's items
Exact due times are in Canvas.
Watch — Professor Messer
Watch — Professor Messer: Malware and Application Attacks (SY0-701)
Free, independent educational resource. Not affiliated with or endorsed by CompTIA. Watch, then read the notes below.
Know these cold
- Malware types: virus (attaches to host file), worm (self-propagates), ransomware (encrypts, demands ransom), Trojan (disguised as legitimate), rootkit (hides in OS), RAT (remote access), spyware (exfiltrates data), keylogger (records keystrokes), adware (displays ads), fileless (lives in memory/registry).
- Application attacks: SQL injection (malicious DB queries via web forms), XSS (injected client-side script), buffer overflow (overwrites adjacent memory), CSRF (forces authenticated user action), directory traversal (../../etc/passwd), command injection.
- Attack chain: Reconnaissance → Weaponization → Delivery → Exploitation → Installation → C2 → Actions (Lockheed Martin Cyber Kill Chain).
Meerk's quiz — open the Lesson 2 gate
10 questions, no time limit. 85% on your first attempt in a 24-hour window opens the gate. Retakes inside the window are practice — they help you learn, they don't count. Work alone; the point is to know it, not to have seen it.
Dinner Table Question
Ask at home: If your employer's website was vulnerable to SQL injection, whose fault would that be?
En español: Si el sitio web de tu empleador fuera vulnerable a inyección SQL, ¿de quién sería la culpa?