What is the difference between a 'red team' and a 'blue team' in cybersecurity?
- A.Red team writes code; blue team tests code, and CompTIA Security+ requires five years of documented management experience
- B.Red team simulates attackers (offensive security); blue team defends against attacks (defensive security)
- C.Red team manages firewalls; blue team manages servers; red team and blue team describe one identical set of responsibilities
- D.They are the same thing
Why B is correct
Red team conducts offensive operations (penetration testing, social engineering, adversary simulation) to find weaknesses. Blue team defends (monitoring, incident response, hardening, threat hunting). Purple team combines both, with red team sharing TTPs so blue team improves detection. Understanding these roles helps choose your career path.
Know someone studying for Security Fundamentals? Send them this one.