Security Foundations: The CIA Triad & Threat Actors
AP Cybersecurity — the CIA triad (Confidentiality, Integrity, Availability), the difference between threat/vulnerability/risk, and the main categories of threat actors.
Every AP Cybersecurity topic connects back to one core model: the CIA triad. Before diving into networks or cryptography, you need to be fluent in this vocabulary — it is the lens the exam uses to frame almost every scenario question.
The CIA triad
- Confidentiality — only authorized people can access the data. Broken by data breaches, eavesdropping, weak access control.
- Integrity — data is accurate and unaltered. Broken by tampering, malware that corrupts files, a man-in-the-middle changing a message in transit.
- Availability — authorized users can access data/systems when they need to. Broken by denial-of-service attacks, ransomware, hardware failure.
A single incident can violate more than one leg of the triad at once — ransomware, for example, breaks availability (files locked) and often confidentiality too (data exfiltrated before encryption).
Threat, vulnerability, and risk — three different words
This distinction is one of the most tested vocabulary points on the exam:
- Vulnerability — a weakness (unpatched software, a weak password policy, an open port).
- Threat — something that could exploit that weakness (an attacker, malware, a natural disaster).
- Risk — the likelihood × impact of a threat exploiting a vulnerability.
An unpatched server (vulnerability) targeted by ransomware (threat) creates a risk to the organization — the risk level depends on how likely the attack is and how damaging it would be.
Categories of threat actors
| Actor | Motivation |
|---|---|
| Script kiddie | Curiosity, low skill, uses existing tools |
| Hacktivist | Political or social cause |
| Organized crime | Financial gain |
| Nation-state | Espionage, sabotage, strategic advantage |
| Insider threat | Employee/contractor, intentional or accidental |
Insider threats are especially tested because they bypass perimeter defenses entirely — the person is already inside the network.
Worked example
A disgruntled employee copies a customer database to a personal USB drive before resigning. Which leg(s) of the CIA triad were violated, and which threat actor category applies?
Confidentiality was violated (unauthorized copy of sensitive data). The threat actor is an insider threat — motivated by grievance, with legitimate access that was misused.
Exam tip
When a scenario question asks you to classify an incident, first identify which leg(s) of the CIA triad were affected, then identify the threat actor category. Answers that name both precisely (not just "a hacker") score higher — the exam rewards exact vocabulary over vague description.
Short Lesson Video
Mock Exam
Practice Quiz
Test yourself: instant results and explanations.
1. Which leg of the CIA triad is violated when a denial-of-service attack takes a website offline?
2. An unpatched web server is an example of a:
3. An employee with legitimate access misuses it to steal company data. This is an example of:
4. Risk is best described as:
Need support with this topic?
In a free 45-minute intro call we assess your level and build a study plan tailored to you.
Free intro call