Topic module

Threat Actors, Attack Vectors and Social Engineering

Security+ threat questions test attacker motivation and capability, social engineering cues, phishing variants, insider risk, and common delivery vectors.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for Security+

Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.

Core concepts

Concept 1

Threat actors differ by motivation, resources, sophistication, and relationship to the organization.

Exam cue: Match attacker profile to motivation and capability.

Concept 2

Social engineering attacks exploit trust, urgency, authority, scarcity, fear, or curiosity.

Exam cue: Identify the manipulation pressure in the scenario.

Concept 3

Attack vectors describe the path used to reach a target, such as email, web, removable media, wireless, cloud, or supply chain.

Exam cue: Separate delivery vector from payload and impact.

Risk pitfalls and guardrails

Calling every phishing attack spear phishing.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Ignoring insider threats because credentials are valid.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Confusing a threat actor with a vulnerability.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Memory anchors

Nation-State Actor

A nation-state actor is usually well-funded, persistent, and tied to geopolitical objectives.

Organized Crime

Organized crime groups usually pursue financial gain through scalable attacks or fraud.

Insider Threat

An insider threat uses authorized access or trusted position to create security risk.

Script Kiddie

A script kiddie uses existing tools with limited sophistication or original capability.

Phishing

Phishing uses deceptive messages to trick users into revealing data or taking unsafe action.

Spear Phishing

Spear phishing targets a specific person or group with tailored information.

Vishing

Vishing uses voice calls or voice messages for social engineering.

Smishing

Smishing uses SMS or text messages for social engineering.

Pretexting

Pretexting builds a false story or role to gain trust and elicit action.

Supply Chain Vector

A supply chain vector compromises a trusted vendor, dependency, update, or service path.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

Investigators find a multi-year espionage campaign using custom implants and infrastructure linked to geopolitical intelligence goals. Which threat actor is most likely?

A group encrypts hundreds of companies and negotiates payments through cryptocurrency. Its objective is primarily revenue. Which actor profile fits best?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.