2.1 Threat Actor Profiles, Motivations, and Attack Vectors
Categorize adversaries from script kiddies to nation-state Advanced Persistent Threats (APTs), evaluating their funding, sophistication, and attack surfaces.
🎯 Key CompTIA Security+ Exam Takeaways
- Advanced Persistent Threats (APTs) are nation-state backed adversaries with vast funding, custom zero-day exploits, and long-term espionage goals.
- Hacktivists are politically or ideologically motivated actors who prioritize public disruption, defacements, and doxxing over financial gain.
- Script kiddies lack custom programming capabilities and rely on pre-packaged, automated scanning and exploit tools found on internet forums.
- Insider threats possess legitimate authorized access and knowledge of internal network topology, making their malicious or negligent actions uniquely dangerous.
- Attack vectors represent the pathways adversaries use to breach defenses: email, unpatched perimeter services, supply chains, and social engineering.
Effective cyber defense requires understanding the adversary. CompTIA classifies threat actors across their technical sophistication, funding resources, intent, and organizational backing. At the apex of capability are Advanced Persistent Threats (APTs). Typically sponsored by sovereign nation-states or military intelligence agencies, APTs possess virtually unlimited financial resources, develop proprietary zero-day exploits, and conduct stealthy, multi-month campaigns aimed at espionage, geopolitical disruption, or critical infrastructure compromise.
In contrast, hacktivists are motivated by political, social, or environmental causes. Rather than stealthy intellectual property theft, hacktivists seek maximum public attention, frequently employing website defacements, distributed denial-of-service (DDoS) floods, and public data leaks. Script kiddies represent low-sophistication attackers who lack deep technical skills and rely on off-the-shelf automated exploit scripts written by others.
Insider threats represent one of the most challenging security risks because the perpetrator already possesses authorized physical access, legitimate domain credentials, and intimate knowledge of where valuable corporate data resides. Defending against insiders requires defense-in-depth: strict least-privilege access, segregation of duties, mandatory data loss prevention (DLP) agents, and behavioral analytics.
⚠️ Common Pearson VUE Exam Traps
- Assuming all hackers are financially motivated; hacktivists seek ideological publicity and nation-states seek geopolitical advantage or strategic intellectual property.
- Underestimating insider threats; malicious or negligent employees bypass perimeter firewalls entirely because they already possess valid credentials.
Knowledge Checkpoint
A defense contractor detects an undetected threat actor operating inside its research network for over eight months. The adversary employed custom zero-day kernel exploits, modified system binaries to evade EDR detection, and methodically exfiltrated aerospace telemetry to a foreign IP range without demanding ransom or disrupting services. Which threat actor profile matches this behavior?