What is the difference between a 'red team' and a 'blue team' in cybersecurity?
- A.A. Red team manages firewalls; blue team manages servers
- B.C. They are the same thing
- C.B. Red team simulates attackers (offensive security); blue team defends against attacks (defensive security)
- D.D. Red team writes code; blue team tests code
Why C is correct
Red team conducts offensive operations (penetration testing, social engineering, adversary simulation) to find weaknesses. Blue team defends (monitoring, incident response, hardening, threat hunting). Purple team combines both, with red team sharing TTPs so blue team improves detection. Understanding these roles helps choose your career path.
Know someone studying for Security Fundamentals? Send them this one.