SY0-701 - Threats, Vulnerabilities, and Mitigations (22% of the exam) - Section 2.1

Compare and contrast common threat actors and motivations.

Distinguish threat actor types such as nation-state, hacktivist, organised crime, insider threat, and shadow IT by their resources, sophistication, and intent. Map common motivations including financial gain, espionage, and service disruption to likely actors, and explain why an actor's capability and goal shape target selection and tactics.

nation-stateinsider threathacktivistshadow ITfinancial vs espionage motivation

Practice question for this objective

Free sampleThreats, Vulnerabilities, and Mitigationseasy

Which attribute most clearly distinguishes a nation-state actor from an unskilled script kiddie?

  • AThe script kiddie typically has greater funding and more advanced bespoke malware than the average nation-state operator.
  • BBoth groups have roughly equal capability and resources, with the only difference being the political alignment of their targets.
  • CNation-state actors are restricted to phishing emails, while script kiddies routinely develop their own zero-day exploits against major operating systems.
  • DNation-state actors have substantial resources, advanced skills, and long-term objectives, while script kiddies have limited skills and short-lived ad hoc goals. Correct
Compare threat actors by attributes such as resources, sophistication, and time horizon to place nation-state and script kiddie at opposite ends. Threat actors are compared along attributes like internal versus external, resources and funding, level of sophistication, and intent or motivation. A nation-state actor sits at the high end of resources and sophistication with strategic long-term goals, while a script kiddie sits at the low end, using publicly available tools for short-lived curiosity or notoriety.

Why A is wrong: This reverses reality. Nation-states command far more funding and tooling, while script kiddies generally rely on borrowed or downloaded tools rather than bespoke malware.

Why B is wrong: Capability and resources differ enormously between the two. Treating them as equivalent ignores the defining contrast in funding, skill, and persistence.

Why C is wrong: Nation-states use a wide arsenal that includes zero-days, and script kiddies typically lack the ability to develop them. The claim swaps the realistic capabilities of each group.

Why D is correct: Resource level, sophistication, and time horizon are the textbook attributes that separate well-funded state operators from opportunistic, low-skill amateurs using ready-made tools.

See more SY0-701 practice questions, answers explained.

Exam traps in Threats, Vulnerabilities, and Mitigations

Answers that look right on this material and are not. Each one is a distractor from a different question in the SY0-701 bank for this domain.

  • Financial motivation only applies to insiders selling data, while espionage motivation only applies to external nation-state operators on the public internet.

    Why it is wrong: Both motivations apply to insiders and outsiders. The word only makes the claim too narrow and ignores well-documented external financial crews and insider espionage cases.

  • Acts on personal grievance after being denied a promotion, abusing access already granted as a trusted employee.

    Why it is wrong: This is tempting because the behaviour is hostile, but it describes an insider threat acting from within, not an externally directed nation-state operation.

  • Both campaigns share an espionage motivation because each results in unauthorised access to sensitive corporate information assets.

    Why it is wrong: Unauthorised access alone does not define espionage; the demand for fast payment in campaign two reveals a financial motive that is distinct from intelligence collection.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.