DEV Community

TiltedLunar123
TiltedLunar123

Posted on

Shadow IT is on the Security+ threat actor list, and there is no attacker in it

Shadow IT sits on the Security+ threat actor list, right there next to nation-states and organized crime. There is no attacker in it. Nobody is breaking in. It is the finance team paying for a file sharing tool on a company card because the approved one takes four days to grant access.

That placement confused me for a while. Once it clicked, a whole category of exam questions got easier, so it is worth explaining.

What the objectives actually name

Pull up CompTIA's Security+ page and read objective 2.1. The threat actors it lists are nation-states, unskilled attackers, hacktivists, insider threats, organized crime, and shadow IT. Motivations get named separately, things like data exfiltration, espionage and financial gain among others.

Two lists. Most people skim straight past that. The exam treats the actor and the motive as separate axes, and most of the questions that feel unfair are questions where you read one and answered the other.

The list is sorted by capability, not by villainy

Shadow IT belongs there because the list sorts threats by what they can do to you and how much warning you get, which is a very different job from ranking them by how villainous they are.

Ask three things about whoever is in the scenario.

How much money and time do they have? A nation-state has effectively unlimited resources and can wait a year. Organized crime is well funded and impatient, because it needs a return. An unskilled attacker has neither.

How capable are they? This is not the same question. Resources buy tools; sophistication is whether they can build something new. A nation-state writes its own malware and burns a zero day when it needs to. Somebody unskilled is running a tool that another person wrote, and does not necessarily know what it does.

Are they inside or outside? Inside changes everything, because internal actors skip the whole first phase. They already have a badge, an account, and a reason to be there.

Run shadow IT through those three and it makes sense. Internal, no hostile intent, minimal sophistication, and yet there is real exposure sitting behind it: company data in a service nobody vetted, and no logging that your team can reach. A security team cannot protect infrastructure it does not know exists. So the slot is earned on capability grounds rather than on intent.

The stem usually hands you the motive

Here is the pattern worth internalizing. Exam questions rarely say "a hacktivist did this." They describe what happened and what the attacker seemed to want, and you work backwards.

Data quietly copied out over months with no ransom demand and no disruption? Long dwell time and no money motive points at espionage, and espionage points at whoever can afford to be patient. Systems encrypted with a payment demand? That is financial gain, and that is organized crime. A public defacement timed to a news story, where the attacker wants you to know? That is philosophical or political, and it is the loudest actor on the list. Nobody quiet does that.

So the useful question is what this person wanted, and who tends to want that, rather than which of four labels you happen to recognize.

There is a corollary that matters just as much. Two actors can run the exact same technique. Phishing is evidence of nobody in particular, because everyone phishes. What separates them is who got targeted and what happened after the attacker got in.

One wording check before you trust your notes

The current objectives say unskilled attacker. Plenty of study material still says script kiddie.

On its own that is harmless, and the terms mean the same thing. It is worth noticing anyway, because it dates the material you are holding. If the wording lines up with an older version of the exam, check the rest of it before you rely on it, since SY0-701 has been the live version since November 2023 and CompTIA now prints a retirement date of June 11 2027 for the English exam.

Where reading stops helping

You can learn all of this from an article, mine included. What none of it prepares you for is the format that gives people the most trouble on the day.

The performance-based questions are not written like this. They drop you into a task and expect you to produce something from a blank state, so you are ordering a rule set or walking a log until the answer falls out. Recognizing a threat actor from a paragraph is a very different skill from operating an interface under time pressure, and studying the first one harder does not do much for the second.

That is the gap I kept hitting, and it is why I ended up building a firewall PBQ you can just do, free and without an account, so people can find out how the format feels before exam day rather than during it. Full disclosure, that one is mine.

For the reading side, Professor Messer's SY0-701 series is free and covers the whole blueprint. Jason Dion's practice exams are the usual next step when you want to be tested rather than taught. And the objectives PDF is free from CompTIA and is the only real checklist, since every question traces back to a numbered line in it.

Threat actors are cheap points once you stop memorizing six labels and start asking what the person wanted and what they could afford. Two questions. They resolve most of the domain.

Top comments (0)