Threat actors, sorted by what they can afford rather than by how scary they sound
Objective 2.1 in this course covers threat actors and motivations — CompTIA's scope note for it compares nation-states, unskilled attackers, hacktivists, insider threats, organized crime, shadow IT, and motivations like data exfiltration, espionage and financial gain. This lesson takes the actors and the attributes that separate them; motivations, shadow IT and the insider are the next lesson.
Why this matters
Domain 2 is 22% of SY0-701 — the second largest — and this objective opens it. The questions are almost always scenarios: you are given a description of an attack and asked which actor it indicates. That is answerable, reliably, if you stop thinking about the actors as personalities and start thinking about them as budgets.
The reason the exam cares is practical rather than trivia. Who you are up against changes what you defend against and how much you spend. A control that stops an unskilled attacker running a downloaded tool is cheap and effective; the same control does nothing against a well-resourced group that will simply try the next thing for eight months.
The lesson
Nation-state, organised crime, hacktivist, insider, unskilled attacker
CompTIA's list, with the distinguishing feature of each:
- Nation-state. Government-backed or government-directed. The defining features are time and funding: they can spend years on one target and develop their own tooling, including exploits nobody else has. Their goal is usually intelligence or strategic advantage rather than money. Often described as an advanced persistent threat (APT).
- Organised crime. Professional, structured, and in it for money. They operate like businesses — specialised roles, affiliates, customer support for ransomware victims. They are well resourced but cost-sensitive in a way nation-states are not: if you are more expensive than the next target, they move on.
- Hacktivist. Motivated by a cause. Skill varies enormously. What characterises them is that publicity is part of the objective — website defacement, data leaks timed to a news cycle, denial of service against a symbolic target. A quiet, undetected hacktivist has failed at their own goal.
- Insider threat. Someone with legitimate access. Resources are modest but position is everything: they start inside, know where things are, and their activity resembles their job. Covered in depth next lesson.
- Unskilled attacker. CompTIA's term for what older material called a "script kiddie". Uses tools others wrote, without deep understanding. Low resources, low sophistication, and high volume — which is why they still matter: they find the unpatched, default-credentialed and internet-exposed.
Two more that appear: shadow IT, which CompTIA lists as a threat actor and which is unusual in having no malicious intent at all (next lesson), and competitors, whose goal is commercial advantage.
Resources, funding and sophistication as the axis that actually separates them
CompTIA describes actors along a small set of attributes, and these are what scenario questions actually hinge on:
- Internal or external — do they start with legitimate access?
- Resources and funding — can they buy zero-days, hire people, sustain an operation for a year?
- Level of sophistication and capability — do they use off-the-shelf tools, or write their own?
Put them on that axis and the scenarios sort themselves:
| Actor | Resources | Sophistication | Tell in a scenario |
|---|---|---|---|
| Nation-state | Very high | Very high | Custom malware, zero-day, months undetected, intelligence target |
| Organised crime | High | High | Ransomware, extortion, payment fraud, clear money motive |
| Hacktivist | Low–medium | Varies | Public statement, defacement, leak, ideological target |
| Insider | Low | Varies | Normal credentials, unusual data access, no intrusion at all |
| Unskilled | Very low | Low | Known tool, known CVE, noisy, opportunistic |
The most reliable single discriminator on the exam is the use of a previously unknown vulnerability. Zero-days are expensive. An actor burning one is telling you they are well funded — nation-state, or the top tier of organised crime.
Internal versus external, and why the insider starts past most of your controls
An external attacker has to solve a problem the insider does not have: getting in. Every perimeter control, every authentication check, every "how do we prevent initial access" investment is aimed at that problem.
The insider begins on the other side of all of it. They have credentials that are supposed to work, on a device that is supposed to be there, doing things that resemble their job. This has three consequences the exam tests:
- Preventive controls are largely irrelevant. You cannot prevent someone using access you gave them.
- Detection has to be behavioural. The signal is not "unauthorised access", it is "access that is authorised but unusual" — volume, timing, breadth. This is why user behaviour analytics exists, and you meet it in Domain 4.
- The controls that work are structural: least privilege, separation of duties, mandatory holidays or job rotation, dual authorisation for high-value actions, and thorough offboarding.
Advanced persistent threat: the word 'persistent' is the load-bearing one
APT is often used loosely to mean "scary attacker". Take the three words literally:
- Advanced — capable, including custom tooling and unknown vulnerabilities, though they will happily use a phishing email if that works.
- Persistent — this is the distinguishing word. They are not after one smash-and-grab. They establish access, maintain it quietly, and stay for months or years. If they are evicted they come back.
- Threat — an organisation with intent and objectives, not a piece of malware.
The security consequence of persistent is the one to carry: incident response against an APT cannot be "remove the malware and move on", because they will have multiple footholds. This is why Domain 4's incident response lesson insists on containment and scoping before eradication.
Matching an actor to a scenario, which is the shape the exam question takes
A short procedure that answers most of these:
- What was the goal? Money → organised crime. Information → nation-state or competitor. A public point → hacktivist. Grievance or gain by someone already inside → insider.
- How long were they there? Months undetected raises nation-state substantially.
- What did they use? A known CVE with a public exploit points down the scale; a zero-day or bespoke implant points up it.
- Did they announce themselves? Announcement is hacktivist or ransomware extortion. Silence is espionage.
- Did they have to break in at all? If not, insider — or an attacker using stolen valid credentials, which is why Domain 4 makes so much of impossible travel and behaviour baselines.
What to take into the exam
- Sort actors by resources and sophistication, not by how dangerous they sound.
- Zero-day use is the strongest single indicator of a well-funded actor.
- Hacktivists need publicity — that is a requirement of their goal, not a mistake.
- The insider's advantage is position, so the answers are behavioural detection and structural controls, not stronger perimeter prevention.
- In APT, "persistent" is the operative word, and it is what makes eradication hard.
Practise what you just read
1. An intrusion used a previously unknown vulnerability and went undetected for eight months. Which actor does this most strongly indicate?
Select one
Show answer
A. Zero-days are expensive, and eight months of undetected presence indicates both capability and patience. That combination points to a well-funded actor pursuing intelligence rather than money. The top tier of organised crime can afford a zero-day, but it will cash out quickly rather than sit quietly.
2. Which attribute most usefully separates threat actors for exam purposes?
Select one
Show answer
B. Sorting by how frightening an actor sounds produces guesses. Sorting by what they can afford and how capable they are produces answers, because the scenario usually tells you what was used and how long it lasted, and both are functions of resources.
3. What does the word 'persistent' contribute to the term advanced persistent threat?
Select one
Show answer
C. Persistent is the operative word. An APT is not after one smash-and-grab; it establishes access, holds it quietly for months or years, and comes back if evicted. That is why incident response against one cannot be 'remove the malware and move on'.
10 more questions on this objective are part of the full course.
Hands-on labs
Part of the free CompTIA Security+ SY0-701 course — 47 lessons and 79 hands-on labs.
This is an independent study companion for CompTIA Security+ SY0-701 and is not produced by or endorsed by CompTIA.