Threat Actors, Attack Vectors and Social Engineering
Security+ threat questions test attacker motivation and capability, social engineering cues, phishing variants, insider risk, and common delivery vectors.
How to study for Security+
Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.
Core concepts
Concept 1
Threat actors differ by motivation, resources, sophistication, and relationship to the organization.
Exam cue: Match attacker profile to motivation and capability.
Concept 2
Social engineering attacks exploit trust, urgency, authority, scarcity, fear, or curiosity.
Exam cue: Identify the manipulation pressure in the scenario.
Concept 3
Attack vectors describe the path used to reach a target, such as email, web, removable media, wireless, cloud, or supply chain.
Exam cue: Separate delivery vector from payload and impact.
Risk pitfalls and guardrails
Calling every phishing attack spear phishing.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Ignoring insider threats because credentials are valid.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Confusing a threat actor with a vulnerability.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Memory anchors
Nation-State Actor
A nation-state actor is usually well-funded, persistent, and tied to geopolitical objectives.
Organized Crime
Organized crime groups usually pursue financial gain through scalable attacks or fraud.
Insider Threat
An insider threat uses authorized access or trusted position to create security risk.
Script Kiddie
A script kiddie uses existing tools with limited sophistication or original capability.
Phishing
Phishing uses deceptive messages to trick users into revealing data or taking unsafe action.
Spear Phishing
Spear phishing targets a specific person or group with tailored information.
Vishing
Vishing uses voice calls or voice messages for social engineering.
Smishing
Smishing uses SMS or text messages for social engineering.
Pretexting
Pretexting builds a false story or role to gain trust and elicit action.
Supply Chain Vector
A supply chain vector compromises a trusted vendor, dependency, update, or service path.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
Investigators find a multi-year espionage campaign using custom implants and infrastructure linked to geopolitical intelligence goals. Which threat actor is most likely?
A group encrypts hundreds of companies and negotiates payments through cryptocurrency. Its objective is primarily revenue. Which actor profile fits best?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
