2.1 Compare and contrast common threat actors and motivations

Domain 2: Threats, Vulnerabilities, and Mitigations

This objective asks you to profile attackers: nation-states, unskilled attackers, hacktivists, insider threats, organized crime, and shadow IT. Each actor pairs with attributes — internal or external, level of sophistication, and resources or funding — and with motivations like data exfiltration, espionage, service disruption, blackmail, financial gain, philosophical or political beliefs, ethical hacking, revenge, disruption, and war. The exam gives you a scenario and expects you to name the most likely actor: a well-funded, patient campaign against defense contractors points to a nation-state; defacing a website over a political grievance points to a hacktivist; an employee installing unapproved cloud tools is shadow IT, not necessarily malicious. Focus on the attribute combinations rather than the labels alone, because distractors reuse plausible actors with the wrong resource level or motivation. Remember that insider threats can be negligent as well as malicious, and shadow IT is a threat actor category on this exam.

What you must know

common pitfall · Candidates match actors by label instead of attributes, picking organized crime for a scenario whose funding, patience, and espionage motive clearly describe a nation-state.

Try a sample question

Which type of threat actor is BEST described as being motivated primarily by philosophical, political, or social causes rather than financial gain?

  • A Organized crime group
  • B Hacktivist
  • C Insider threat
  • D Unskilled attacker
Show answer & explanations
  • A Organized crime groups are almost always financially motivated, running operations such as ransomware, fraud, and data theft to generate revenue rather than to advance an ideological cause.
  • B correct ·Correct. Hacktivists attack targets to promote a political, social, or philosophical agenda, often through defacement, data leaks, or denial of service, with ideology rather than profit as the primary driver.
  • C Insider threats operate from within the organization and are typically motivated by revenge, personal financial gain, or simple carelessness, not primarily by an outside political or social cause.
  • D Unskilled attackers, sometimes called script kiddies, are usually motivated by curiosity, notoriety, or the thrill of disruption, and they rely on prebuilt tools rather than pursuing ideological goals.

sample item — the full bank runs 450+ questions at exam difficulty

Is objective 2.1 your weak spot?

The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.

Check my readiness — free