Threat Actor Types for Security+
Short answer
Threat actor type is about who or what source of behavior best explains the scenario. It is not the same as the attack vector or the motivation, although the clues often overlap. A nation-state actor is likely when the prompt emphasizes government interests, geopolitical targets, long-term intelligence collection, military advantage, sanctions, critical infrastructure, or unusually patient operations. The exam does not require naming the country or proving attribution; it expects recognition of the actor class.
Why it appears on the exam
SY0-701 2.1: Compare common threat actor types such as nation-state, unskilled attacker, hacktivist, insider, organized crime, and shadow IT.
Key concepts
Concept 1
How Threat Actor Types works
Threat actor type is about who or what source of behavior best explains the scenario. It is not the same as the attack vector or the motivation, although the clues often overlap. A nation-state actor is likely when the prompt emphasizes government interests, geopolitical targets, long-term intelligence collection, military advantage, sanctions, critical infrastructure, or unusually patient operations. The exam does not require naming the country or proving attribution; it expects recognition of the actor class.
Example
A group targets defense contractors for years to collect research useful to a foreign military. The best actor type is nation-state.
Concept 2
Common confusion
Learners often treat motivation as the actor type. Financial gain is a motivation; organized crime is an actor type commonly associated with it. Espionage is a motivation; nation-state is an actor type commonly associated with it. Legitimate access is the key insider clue even when the insider's motivation is revenge, money, convenience, or negligence.
Example
A person runs a downloaded scanner against random internet hosts and tries default passwords. The best actor type is unskilled attacker.
Concept 3
What to recognize
Classify a scenario as nation-state, unskilled attacker, hacktivist, insider threat, organized crime, or shadow IT; Explain why a clue supports one actor type over a neighboring type; Recognize shadow IT as an internal unsanctioned technology risk source, not necessarily a malicious attacker; Distinguish actor type from motivation, vector, vulnerability, indicator, and mitigation.
Example
A group defaces a company site after a controversial policy announcement and posts a political message. The best actor type is hacktivist.
Sample questions
Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.
Q1.A Security+ scenario describes this situation: A group targets defense contractors for years to collect research useful to a foreign military. The best actor type is nation-state. Which answer fits best?
Q2.A Security+ scenario centers on Threat Actor Types. Which answer is the closest lesson match?
Q3.A Security+ scenario about Threat Actor Types looks similar to a nearby topic. What should you do before choosing an answer?
Practice this lesson in Cultiv8
The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.
Continue in Cultiv8