Security+ Lesson

Threat Actor Attributes for Security+

Last updated: 6/10/2026

Short answer

Actor attributes help compare likely risk even when the exact actor type is uncertain. Internal and external describe position relative to the organization. An insider threat, shadow IT user, compromised employee account, contractor account, or trusted partner connection can be internal because it benefits from existing trust. An internet-based attacker, criminal affiliate, hacktivist group, or nation-state team can be external when it approaches from outside normal authorization. The key is the starting trust relationship, not whether traffic crosses a firewall.

Why it appears on the exam

SY0-701 2.1: Assess threat actors by internal versus external position, resources, funding, sophistication, and capability.

Key concepts

Concept 1

How Threat Actor Attributes works

Actor attributes help compare likely risk even when the exact actor type is uncertain. Internal and external describe position relative to the organization. An insider threat, shadow IT user, compromised employee account, contractor account, or trusted partner connection can be internal because it benefits from existing trust. An internet-based attacker, criminal affiliate, hacktivist group, or nation-state team can be external when it approaches from outside normal authorization. The key is the starting trust relationship, not whether traffic crosses a firewall.

Example

A contractor with valid virtual private network (VPN) access copies files from a project share. The position attribute is internal because trusted access is central.

Concept 2

Common confusion

Learners often equate funding, resources, sophistication, and capability. Funding is money. Resources are everything the actor can bring to the operation. Sophistication is how advanced the methods are. Capability is what the actor can actually accomplish in the given environment. These attributes often correlate, but Security+ questions may separate them.

Example

A botnet operator attacks a public website from many unrelated networks. The position attribute is external; resource clues include distributed infrastructure.

Concept 3

What to recognize

Identify internal versus external actor position from scenario clues; Compare funding, resources, sophistication, and capability; Explain why legitimate access can increase capability even without advanced skill; Recognize that high impact does not automatically prove high sophistication.

Example

A group builds custom malware, registers staging domains, and changes tactics when blocked. The scenario indicates higher sophistication.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.A Security+ scenario describes this situation: A contractor with valid VPN access copies files from a project share. The position attribute is internal because trusted access is central. Which answer fits best?

Q2.A Security+ scenario centers on Threat Actor Attributes. Which answer is the closest lesson match?

Q3.A Security+ scenario about Threat Actor Attributes looks similar to a nearby topic. What should you do before choosing an answer?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8