2.1 Compare and contrast common threat actors and motivations
Objective 2.1 sits in Threats, Vulnerabilities, and Mitigations, which carries 22% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.
Objective title verbatim from the official objectives. CompTIA exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
Which term describes an unsanctioned application or cloud service that employees adopt without approval from the IT department?
The concept
Shadow IT refers to unapproved technology used within an organization.
Why this answer
Shadow IT specifically describes systems or apps deployed without IT department knowledge or approval.
- Correct: matches the definition of unauthorized, unapproved technology.
- BInsider threat involves misuse of authorized access, not merely unapproved tools.
- CUnskilled attacker describes an external actor's skill level, not internal tool sanctioning.
- DHacktivist describes motivation, not unauthorized technology adoption.
Now you: objective 2.1 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 2
Three staff in one finance team receive messages referencing a real supplier invoice and their manager by name. No other department is contacted. What does the targeting indicate?
Sample question 2 of 2
An account belonging to a departed contractor is used to sign in to the corporate VPN at 03:00. The credential is valid and no exploit is involved. Why is this hard to detect?
That’s 2 of the full Security+ bank.
Keep going free: 10 questions per certification in bank practice, with no account.
Continue practicingRead the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.