A security operations team at a financial technology firm discovers that an external adversary maintained undetected access inside their cloud development pipeline for over eight months. The adversary utilized custom zero-day exploits, digitally signed binary payloads, and target-tailored command-and-control channels to exfiltrate proprietary trading algorithms without demanding ransom or disrupting services. Which of the following threat actor attributes and attack vectors are demonstrated in this scenario? (Select TWO.)
- High operational sophistication and substantial resource backing characteristic of a nation-state threat actor.Answer
- Strategic attack vectors leveraging zero-day vulnerabilities and compromised software supply chain components.Answer
- CFinancial gain motivation driven by opportunistic ransomware deployment from an organized cybercrime syndicate.
- DNon-malicious insider threat behavior caused by unapproved shadow IT applications.
Answer
The correct answers identify high operational sophistication with nation-state backing and the use of strategic zero-day and supply chain attack vectors.
The scenario describes an Advanced Persistent Threat (APT) possessing high technical sophistication, extensive financial/technological resources, and long-term patience typical of nation-state threat actors. Furthermore, infiltrating a cloud development environment via zero-day vulnerabilities exemplifies modern supply chain and third-party development attack vectors.
Step-by-Step Solution
Key Concept
Threat Actor Attributes and Attack Vectors