During a routine audit at an aerospace software supplier, cybersecurity analysts discover that a lead avionics developer installed an unapproved third-party cloud synchronization tool on a secure build workstation. The investigation reveals the developer used the application to bypass network throttling and meet a tight project deadline, with no intent to exfiltrate data or compromise systems. Which threat actor classification and primary attribute best describe this developer's actions?
- Shadow IT / Non-malicious insider characterized by lack of malicious intent and unauthorized workaround of corporate security controlsAnswer
- BNation-state threat actor characterized by high technical sophistication and intent to conduct advanced persistent espionage
- CHacktivist threat actor characterized by ideological motivation and desire to cause public operational disruption
- DOrganized crime threat actor characterized by financial extortion motives and deployment of ransomware vectors
Answer
Shadow IT / Non-malicious insider characterized by lack of malicious intent and unauthorized workaround of corporate security controls
The correct answer identifies the individual as a non-malicious insider operating under Shadow IT because the developer is an authorized internal user who deployed unauthorized software solely to complete work duties faster, lacking any hostile or malicious intent.
Step-by-Step Solution
Key Concept
Threat Actor Attributes and Shadow IT
Estimated Time:1m 15s