Objective 2.1SY0-701

2.1 Compare and contrast common threat actors and motivations

Objective 2.1 sits in Threats, Vulnerabilities, and Mitigations, which carries 22% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Threats, Vulnerabilities, and MitigationsEasy

Which term describes an unsanctioned application or cloud service that employees adopt without approval from the IT department?

Correct.

The concept

Shadow IT refers to unapproved technology used within an organization.

Why this answer

Shadow IT specifically describes systems or apps deployed without IT department knowledge or approval.

  • Correct: matches the definition of unauthorized, unapproved technology.
  • BInsider threat involves misuse of authorized access, not merely unapproved tools.
  • CUnskilled attacker describes an external actor's skill level, not internal tool sanctioning.
  • DHacktivist describes motivation, not unauthorized technology adoption.
Read the sourceMicrosoft Learn: Azure threat detection
Verified against owasp.org · 2026-07-27
threat-actorsshadow-it

Now you: objective 2.1 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 2

Threats, Vulnerabilities, and MitigationsModerate

Three staff in one finance team receive messages referencing a real supplier invoice and their manager by name. No other department is contacted. What does the targeting indicate?

Sample question 2 of 2

Threats, Vulnerabilities, and MitigationsModerate

An account belonging to a departed contractor is used to sign in to the corporate VPN at 03:00. The credential is valid and no exploit is involved. Why is this hard to detect?

That’s 2 of the full Security+ bank.

Keep going free: 10 questions per certification in bank practice, with no account.

Continue practicing

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Threats, Vulnerabilities, and Mitigations