CompTIA SY0-701: Threat Actors and Attack Vectors

Threat analysis starts with two different questions: who is likely to attack, and how are they likely to reach the target? The CompTIA Security+ SY0-701 objectives treat threat actors, motivations and attack vectors as connected ideas because security teams make better defensive choices when they understand both the adversary and the path that adversary is most likely to use.

A threat actor is the person, group or organization capable of causing harm. An attack vector is the route or mechanism used to reach a system, account, user or physical asset. Exam scenarios often give clues about both. A financially motivated criminal group using stolen credentials has a different profile from a disgruntled employee copying data through an authorized account, even if both ultimately cause a confidentiality breach.

The practical skill is not memorizing labels in isolation. Candidates need to infer likely capability, resources, access and motivation, then connect those characteristics to the attack surface that is exposed.

Threat actors differ in capability, resources and access

Nation-state actors are usually associated with substantial resources, patience and strategic objectives such as espionage, geopolitical advantage or disruption. They may invest in custom tooling, supply-chain compromise and long-term persistence because the value of the target justifies a slow campaign.

Organized criminal groups tend to be financially driven. Credential theft, ransomware, payment fraud and data extortion fit that model because they can be monetized. Hacktivists, by contrast, are commonly motivated by ideology or publicity. Their operations may focus on disruption, defacement, leaks or denial of service rather than direct financial return.

Insiders are different because access may already be legitimate. An employee, contractor or partner can misuse authorized access intentionally, or cause damage unintentionally through negligence. This is why insider risk cannot be managed only with perimeter defenses. Least privilege, logging, data controls and separation of duties remain important even for trusted users.

Motivation helps predict what an attacker values

Financial gain, espionage, revenge, ideology, disruption and competitive advantage create different incentives. A criminal actor may move quickly toward systems that support payment or extortion, while an espionage campaign may prioritize quiet persistence and access to sensitive intellectual property.

Motivation also affects the attacker’s tolerance for visibility. A destructive actor may not care whether defenders detect the attack if the goal is to interrupt operations. An intelligence-focused adversary often values stealth because access is useful only while it remains undiscovered.

For Security+, the useful habit is to ask what the actor wants after compromise. The answer often explains why one target, persistence mechanism or exfiltration technique makes more sense than another.

External and internal actors create different trust problems

External attackers begin outside the organization’s normal trust boundaries. They may probe public applications, remote-access services, cloud identities, exposed APIs or users through social engineering. Defenders therefore need strong internet-facing controls, identity protection and monitoring of unusual access patterns.

Internal actors begin with some level of authorized access or physical proximity. Their advantage is not necessarily advanced technical skill; it is familiarity and access. An employee may know where sensitive files are stored, which business process has weak oversight, or which shared account is rarely reviewed.

This difference is one reason zero-trust principles are useful beyond internet threats. Internal location should not create unlimited confidence. The broader CompTIA cybersecurity certifications path repeatedly returns to least privilege because trusted access still needs boundaries.

Social engineering attacks the decision-making process

Phishing, smishing, vishing, pretexting, impersonation and business-email compromise target people rather than software flaws. The attacker tries to create urgency, authority, fear, curiosity or familiarity so the victim takes an action that benefits the attacker.

Phishing messages may deliver malicious links or attachments, but the important concept is manipulation. Spear phishing narrows the target and personalizes the message. Whaling focuses on senior or high-value individuals. Business-email compromise can exploit compromised mailboxes or convincing impersonation to redirect payments or obtain sensitive information.

Physical social engineering matters too. Tailgating, piggybacking and shoulder surfing bypass technical controls by exploiting human behavior. The site’s discussion of common social-engineering attacks is useful because these scenarios often look simple until the candidate identifies the exact control that failed.

Credential attacks turn identity into an attack vector

Passwords and authentication tokens are high-value targets because valid credentials can make malicious activity look legitimate. Password spraying tests a small number of common passwords against many accounts, reducing the likelihood of triggering lockout policies. Brute force repeatedly tries many values against a specific target, while credential stuffing reuses username-and-password pairs stolen from other services.

Attackers may also steal session tokens, cookies or API keys. In those cases the problem is not guessing the password; it is obtaining an artifact that represents an already authenticated identity. Strong multifactor authentication helps, but session security, conditional access and token protection matter as well.

When an exam question involves repeated login attempts, first determine whether the attacker is targeting one account with many passwords, many accounts with a few passwords, or previously breached credentials. That distinction points to the correct attack type and often the most useful mitigation.

Application and web vectors exploit exposed logic

Public applications create an obvious path into an organization because they must accept input from untrusted users. Injection attacks occur when untrusted data is interpreted as commands or queries. Cross-site scripting causes attacker-controlled script content to run in a user’s browser. Directory traversal attempts to reach files outside the intended application path.

Security+ does not require deep exploit development, but it does expect candidates to recognize the relationship between input, execution and trust boundaries. Secure coding, input validation, parameterized queries, output encoding and least privilege can reduce exposure depending on the flaw.

The attack surface extends beyond websites. APIs, mobile applications, third-party integrations and cloud functions can expose similar trust problems. The underlying question is whether external input is being accepted, validated and authorized safely.

Network vectors exploit exposure, weak protocols and trust relationships

Network attacks can target services directly, manipulate traffic or exploit the assumptions systems make about one another. On-path attacks, spoofing, poisoning and rogue services attempt to redirect or observe communications. Denial-of-service attacks focus on availability by consuming bandwidth, connections or application resources.

Wireless networks add their own exposure because radio signals extend beyond physical walls. Rogue access points and evil-twin networks can lure users into unsafe connections, while weak wireless configurations can make unauthorized access easier. Network segmentation, secure protocols and strong authentication reduce the impact of a successful foothold.

The broader enterprise threat landscape shows why network attacks are rarely isolated. A network vector may be only the first step before credential theft, privilege escalation or data exfiltration.

Supply-chain compromise attacks trusted dependencies

Organizations depend on software vendors, service providers, libraries, contractors and managed services. That creates a supply-chain attack surface. Instead of attacking the final target directly, an adversary may compromise a dependency that already has trusted access, privileged software distribution or a business relationship with the victim.

The defensive challenge is that normal trust signals can still be present. A software update may be digitally signed by a compromised vendor. A partner account may be valid even though the partner environment was breached. Third-party risk management therefore needs technical controls and governance rather than a one-time vendor approval.

Security+ scenarios may describe a compromise arriving through a vendor, managed service, open-source component or software update. The defining feature is that the attacker used a trusted dependency as the path.

Physical vectors remain relevant in hybrid environments

Physical access can bypass controls that look strong on paper. An attacker may connect a rogue device, steal removable media, access an unattended workstation or enter a restricted area. Environmental and facility controls therefore remain part of cybersecurity.

Badges, locks, guards, mantraps, cameras and visitor procedures reduce physical exposure, but the control choice depends on the risk. A camera is useful for detection and deterrence, while a locked rack or mantrap can directly restrict access.

The site’s explanation of physical security controls reinforces a common Security+ lesson: technical security is only one layer of a complete defense.

Indicators help connect an attack vector to observed behavior

After an attack begins, defenders see evidence rather than the attacker’s intent. Unusual authentication failures, impossible travel, new administrative accounts, unexplained outbound traffic, suspicious processes and modified system files can all become indicators.

One indicator rarely proves the full attack story. A spike in failed logins may represent password spraying, a user mistake or a misconfigured application. Correlation matters. Multiple signals across identity, endpoint and network telemetry can reveal a sequence that makes the actor and vector clearer.

This is why Security+ links threat recognition with monitoring and incident response. Threat intelligence gives hypotheses; logs and telemetry provide evidence.

Mitigation should break the attack path, not just name the threat

A useful mitigation changes the attacker’s probability of success. Multifactor authentication can reduce the impact of stolen passwords. Network segmentation can limit lateral movement. Application hardening reduces exposed weaknesses. User awareness can reduce the success rate of social engineering.

The best answer in a scenario depends on where the attack path is vulnerable. A control that is generally “good security” may be irrelevant to the specific vector. Installing a firewall does not fix malicious macros in email attachments, just as awareness training does not patch a vulnerable internet-facing service.

The firewall security model is a good example: firewalls are important, but they address defined traffic paths and policy decisions rather than every possible threat.

Study actor, motive, vector and mitigation as one chain

For SY0-701, do not memorize threat actors in one list and attack vectors in another. Build a chain: identify the actor, infer the motivation, identify the exposed path, predict the likely objective and select controls that interrupt that path.

A state-sponsored actor targeting intellectual property through a compromised supplier suggests patience, stealth and supply-chain risk. A criminal group sending credential-phishing messages suggests financial motivation and identity abuse. A disgruntled administrator copying confidential data suggests insider risk and misuse of legitimate privilege.

The main CompTIA certification inventory shows how Security+ sits between foundational IT knowledge and more specialized defensive or offensive security credentials. Within SY0-701, threat actors and attack vectors matter because every later discussion of vulnerability management, architecture, monitoring and incident response begins with understanding what the defender is trying to stop.