These exercise teams describe the two sides of a security engagement and the bridge between them. Red attacks, blue defends, and purple makes sure the two actually learn from each other. The exam uses the color to signal the role.
Last updated July 2026
| Aspect | Red team | Blue team | Purple team |
|---|---|---|---|
| Role | Offense: simulate real attackers | Defense: detect and respond | Collaboration: connect offense and defense |
| Goal | Find and exploit weaknesses | Stop, detect, and contain attacks | Maximize learning from each exercise |
| Mindset | Think like an adversary | Monitor, harden, and respond | Share findings in real time |
| Typical activities | Penetration testing, social engineering, exploitation | SOC monitoring, log analysis, incident response, hardening | Joint debriefs, feedback loop, tuning detections |
| Output | A report of what they got into | Stronger detections and response | Concrete improvements both sides adopt |
Red is the attacker, blue is the defender, and purple is less a standing team than the working relationship that makes red and blue improve each other. A good purple-team exercise has the red team show exactly how it got in while the blue team tunes detections to catch it next time. Also know the white team: the referees who run the exercise.
Reading the difference is a start. SecPlus Mastery drills it with over 1,000 practice questions, timed mock exams, and spaced review across all five SY0-701 domains, so it sticks for exam day.
Written to the CompTIA Security+ SY0-701 objectives. CompTIA and Security+ are trademarks of CompTIA, used here for identification only.