Question

Difficulty: MediumThreat Actors, Attributes, and Attack Vectors

An enterprise security architecture team at a telecommunications firm is updating their threat landscape documentation. Match each threat actor category on the left with its primary operational attributes, resources, and attack vector characteristics on the right.

  • Nation-state / Advanced Persistent Threat (APT)Extremely high sophistication and significant funding; targets high-value intelligence via stealthy zero-day exploits and supply chain compromises.
  • Disgruntled InsiderVariable technical skill with existing authorized access; motivated by personal grievances to sabotage systems or exfiltrate sensitive internal data.
  • Hacktivist CollectiveModerate sophistication motivated by political or ideological causes; relies on public disruptive attacks like website defacement and distributed denial-of-service (DDoS).
  • Shadow ITLow malicious intent; motivated by operational convenience, introducing unvetted cloud software and misconfigured assets outside official security oversight.

Answer

Nation-state / APT matches with high sophistication, state funding, and supply chain/zero-day vectors. Disgruntled Insider matches with legitimate access, personal motivation, and internal sabotage/exfiltration vectors. Hacktivist Collective matches with ideological motivation and high-visibility DDoS/defacement vectors. Shadow IT matches with operational convenience lacking malicious intent, introducing unvetted assets.
Correctly matching threat actors requires aligning their core motivations, sophistication levels, resource availability, and primary attack mechanisms. Nation-state actors rely on heavy funding and stealth (zero-days/supply chain); insiders leverage authorized access; hacktivists target public visibility for ideological causes; and shadow IT introduces risks unintentionally due to unapproved operational workarounds.

Step-by-Step Solution

1
Analyze the resources and motivation of Nation-state actors.
Identify that state-sponsored APT groups have high funding and use covert vectors like zero-days and supply chain intrusions.
Nation-states focus on long-term espionage requiring significant capital and advanced expertise.
2
Evaluate internal threats acting out of revenge or financial gain.
Identify that disgruntled insiders utilize established system access and privilege.
Insiders bypass perimeter controls naturally because they hold legitimate user accounts.
3
Examine ideological threat actors and their typical goals.
Match hacktivists with political motives and public disruption tactics like DDoS.
Hacktivist success relies on public attention and statement-making rather than hidden data theft.
4
Differentiate unsanctioned internal IT usage from intentional attacks.
Match Shadow IT with non-malicious employee workarounds that expose cloud assets.
Shadow IT stems from a desire for efficiency, leading to security blind spots.

Key Concept

Threat Actor Classifications, Attributes, and Attack Vector Characteristics
Rate this question