TechKnowSurge
CompTIA Security+ 2.2 Cisco CCST Cybersecurity 1.2 CompTIA Tech+ 6.3 Cisco CyberOps Associate 2.1 Cisco CCST Cybersecurity 1.1
InteractiveSecurityFree

Map the Attack Surface

Label the entry points into a small office with the attack vector each one represents, and see the attack surface as all of them together.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Every numbered spot on this office is a different way in, and that is the whole idea of an attack surface: not one door, but every door, cable, signal and person an attacker could use, taken together. The dashed line around the scene is that surface. Each individual way in — the one an attacker actually picks — is an attack vector. The physical vectors are the ones you could walk up to. Someone slipping through the badge-controlled front door right behind an employee is Tailgating: the lock works, but a person held it open. A stranger's box plugged into a wall jack is the Wired Network — get inside the building and the network is one cable away. A USB stick left on the floor is Removable Media, counting on someone curious enough to plug it in. The digital vectors come in over the network. The gap in the firewall that lets internet traffic reach the web server is an Open Service Port — opened on purpose so customers can reach the site, and a way in for anyone who finds a weakness behind it. The Wi-Fi signal is the Wireless Network, and it is the reason the dashed line bulges outside the wall: radio doesn't stop at the building, so a car in the parking lot is inside the attack surface. The printer still wearing its admin/admin sticker is Default Credentials — a factory login anyone can look up. The human vectors work on people rather than machines. The hooked email is a Phishing Email and the ringing phone is a Voice Call — both are contact an attacker uses to talk someone into doing the work for them. The last two sit outside the building entirely, which is exactly why they are easy to forget. The truck delivering a new switch is Vendor Hardware: equipment can arrive already flawed or tampered with. The outsourced help desk with a remote link into the server room is a Service Provider: if they are breached, their access becomes the attacker's. Both are the supply chain — other organizations' security becoming part of yours.

What you'll learn

Aligned to

CompTIA Security+
2.2 Explain common threat vectors and attack surfaces.
Cisco CCST Cybersecurity
1.2 Explain common threats and vulnerabilities
1.1 Define essential security principles
CompTIA Tech+
6.3 Summarize behavioral security concepts.
Cisco CyberOps Associate
2.1 Compare attack surface and vulnerability

Key terms

Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Attack Vector
The specific path or method a threat actor uses to gain unauthorized access to a system or network, such as a phishing email, an unpatched vulnerability, or a misconfigured network port.
Tailgating
A physical security breach where an unauthorized person follows an authorized individual through a secured entry point without presenting credentials.
Wireless Access Point
WAP
A device that allows wireless devices to connect to a wired network using Wi-Fi.
Firewall
A network security device that monitors and controls incoming and outgoing traffic based on predefined security rules.
Removable Media
Portable storage devices such as USB flash drives, SD cards, and optical discs that can be detached from a computer and used to transport, distribute, or back up data.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Vishing
A voice-based social engineering attack in which an attacker uses phone calls or voice messages to manipulate targets into revealing sensitive information or taking a harmful action such as transferring funds or resetting credentials.
Default Credentials
Factory-set usernames and passwords that ship with network devices, applications, and services. Default credentials must be changed immediately upon deployment because they are publicly documented and frequently targeted by automated attackers.
Supply Chain
The network of vendors, suppliers, and service providers whose hardware, software, or services an organization depends on, each representing a potential source of security vulnerability.
Managed Service Provider
MSP
A third-party company that remotely manages a customer's IT infrastructure or end-user systems. MSPs can introduce shared security risks; a compromised MSP can serve as a launchpad for attacks against all of its clients simultaneously.

Topics

Interactive Label Diagram

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →