CompTIA Security+ SY0-701 · Free study guide
Objective 2.1 — Distinguish threat actors and their motivations
Threat-actor analysis guides defensive priorities, but attribution is an evidence-weighted hypothesis—not a label inferred from one tool or dramatic note. Start with observable behavior: target selection, access path, persistence, operating hours, tooling, data sought, and actions after access. Then compare likely actor attributes and motivations.
Nation-state operators may have sustained funding, custom capability, patience, and espionage or strategic-disruption goals. Organized crime commonly pursues financial gain through theft, fraud, extortion, and ransomware. Hacktivists align activity with political or philosophical goals and may seek publicity or disruption. An unskilled attacker often relies on public tools and opportunistic exposure. Capability varies within every group, so tool sophistication alone is not decisive.
Access changes the investigation
An insider already has some legitimate access or organizational knowledge. The person may act deliberately for money, revenge, or coercion, or cause harm unintentionally. An external actor must first obtain access but may later operate through a compromised internal account. “Internal account” therefore does not prove “internal actor.” Compare authentication history, device ownership, normal duties, and data-access patterns.
Shadow IT describes technology introduced outside approved governance. It may be created to solve a business problem rather than to attack the organization, yet it expands risk by bypassing inventory, configuration, logging, retention, and vendor review. Treat the behavior and control gap seriously without assuming malicious intent.
Ethical researchers may discover vulnerabilities while acting under a responsible-disclosure or authorized-testing program. Authorization and rules of engagement distinguish approved activity from unauthorized access—not the researcher’s stated motivation.
Motivation shapes likely actions
Espionage emphasizes durable access and selective collection. Financially motivated actors may monetize accounts, payment data, or extortion quickly. Ideological actors may leak information or disrupt a visible service. Revenge can focus on a former employer or specific manager. War and strategic disruption may target critical services. Blackmail needs leverage, while data exfiltration may serve several motivations.
Use confidence language in reporting: “evidence is consistent with” is more defensible than “proved.” Record alternative explanations and intelligence gaps. Defensive actions should address the observed techniques even when attribution remains uncertain.
Decision rule: combine access, resources, capability, target, and behavior; never choose an actor solely because one motivation or tool could fit.
Practice and apply this objective
A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.
Start practicing free