SY0-701 - Threats, Vulnerabilities, and Mitigations - Section 2.1

Compare and contrast common threat actors and motivations.

Distinguish threat actor types such as nation-state, hacktivist, organised crime, insider threat, and shadow IT by their resources, sophistication, and intent. Map common motivations including financial gain, espionage, and service disruption to likely actors, and explain why an actor's capability and goal shape target selection and tactics.

nation-stateinsider threathacktivistshadow ITfinancial vs espionage motivation

Practice question for this objective

Free sampleThreats, Vulnerabilities, and Mitigationseasy

Which attribute most clearly distinguishes a nation-state actor from an unskilled script kiddie?

  • AThe script kiddie typically has greater funding and more advanced bespoke malware than the average nation-state operator.
  • BBoth groups have roughly equal capability and resources, with the only difference being the political alignment of their targets.
  • CNation-state actors are restricted to phishing emails, while script kiddies routinely develop their own zero-day exploits against major operating systems.
  • DNation-state actors have substantial resources, advanced skills, and long-term objectives, while script kiddies have limited skills and short-lived ad hoc goals. Correct
Compare threat actors by attributes such as resources, sophistication, and time horizon to place nation-state and script kiddie at opposite ends. Threat actors are compared along attributes like internal versus external, resources and funding, level of sophistication, and intent or motivation. A nation-state actor sits at the high end of resources and sophistication with strategic long-term goals, while a script kiddie sits at the low end, using publicly available tools for short-lived curiosity or notoriety.

Why A is wrong: This reverses reality. Nation-states command far more funding and tooling, while script kiddies generally rely on borrowed or downloaded tools rather than bespoke malware.

Why B is wrong: Capability and resources differ enormously between the two. Treating them as equivalent ignores the defining contrast in funding, skill, and persistence.

Why C is wrong: Nation-states use a wide arsenal that includes zero-days, and script kiddies typically lack the ability to develop them. The claim swaps the realistic capabilities of each group.

Why D is correct: Resource level, sophistication, and time horizon are the textbook attributes that separate well-funded state operators from opportunistic, low-skill amateurs using ready-made tools.

See more SY0-701 practice questions, answers explained.

More in this domain

Back to all Threats, Vulnerabilities, and Mitigations objectives, or the SY0-701 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.