A university research laboratory discovers that confidential quantum computing project files were accessed by an unauthorized external party. The investigation reveals that a lead researcher had set up an unapproved personal cloud storage folder to easily share files with external colleagues, bypassing university security controls. The external party accessed the folder by running automated public scripts that guessed default administrative credentials on the storage service. Which of the following threat actor attributes and attack vectors are demonstrated in this scenario? (Select TWO.)
- Shadow IT deployment serving as an attack vectorAnswer
- Low sophistication level of the external threat actorAnswer
- CAdvanced persistent threat (APT) capabilities funded by a nation-state
- DDirect physical access attack vector against on-premises infrastructure
Answer
Shadow IT deployment serving as an attack vector AND Low sophistication level of the external threat actor.
The scenario highlights two distinct elements: an internal employee deploying unapproved personal cloud services (Shadow IT serving as an attack vector) and an external attacker utilizing simple automated default credential guessing (demonstrating low technical sophistication).
Step-by-Step Solution
Key Concept
Threat Actor Attributes and Attack Vectors