Question

Difficulty: MediumThreat Actors, Attributes, and Attack Vectors

A security operations team at a commercial satellite communications provider is evaluating two separate security incidents to classify the underlying threat actors and their attack vectors based on observed operational attributes.

• Incident 1: A prolonged, highly sophisticated intrusion into ground station controller firmware utilizing zero-day exploits and custom memory-resident malware, sustained over nine months with no apparent financial extortion attempt.
• Incident 2: A sudden web defacement of the public customer portal paired with a high-volume volumetric DDoS attack, accompanied by public statements demanding the cancellation of aerospace defense contracts.

Based on these attributes and operational indicators, which of the following threat actor classifications and profile assessments are correct? (Select TWO.)

  1. Incident 1 is best classified as a nation-state threat actor operating with high sophistication, extensive funding, and persistent advanced capabilities.Answer
  2. Incident 2 is best classified as a hacktivist group motivated by ideological causes and relying primarily on widely available disruptive attack vectors.Answer
  3. C
    Incident 1 is best classified as an insider threat leveraging elevated privilege access for opportunistic personal financial gain.
  4. D
    Incident 2 is best classified as an organized crime syndicate leveraging bespoke ransomware binaries for commercial extortion.

Answer

Incident 1 represents a nation-state threat actor characterized by high sophistication and persistence, while Incident 2 represents a hacktivist group driven by ideological motivations utilizing disruptive attack vectors.
The correct selections accurately align threat actor profiles with their defining attributes: Incident 1 demonstrates the persistent stealth, custom tooling, and high sophistication characteristic of nation-state actors, while Incident 2 displays the ideological motivation and disruptive public vectors characteristic of hacktivist groups.

Step-by-Step Solution

1
Analyze Incident 1 attributes
Identified long-term persistence (9 months), zero-day exploit usage, custom memory-only malware, and strategic intelligence gathering without financial demands.
These characteristics align directly with nation-state Advanced Persistent Threat (APT) actors who possess vast resources and technical sophistication.
2
Analyze Incident 2 attributes
Identified public website defacement, volumetric DDoS, low-to-moderate technical complexity, and ideological demands regarding defense contracts.
These indicators match hacktivist profiles, where political or social ideology drives disruptive public attacks rather than financial extortion.
3
Evaluate and select the matching options
Selected the statements accurately characterizing the nation-state actor for Incident 1 and the hacktivist group for Incident 2.
Threat actor categorization depends on evaluating motivation, resources, sophistication, and intent against observed incident indicators.

Key Concept

Threat Actor Attributes, Motivations, and Attack Vectors
Estimated Time:1m 30s
Rate this question