Question

Difficulty: MediumThreat Actors, Attributes, and Attack Vectors

During a routine audit at an aerospace software supplier, cybersecurity analysts discover that a lead avionics developer installed an unapproved third-party cloud synchronization tool on a secure build workstation. The investigation reveals the developer used the application to bypass network throttling and meet a tight project deadline, with no intent to exfiltrate data or compromise systems. Which threat actor classification and primary attribute best describe this developer's actions?

  1. Shadow IT / Non-malicious insider characterized by lack of malicious intent and unauthorized workaround of corporate security controlsAnswer
  2. B
    Nation-state threat actor characterized by high technical sophistication and intent to conduct advanced persistent espionage
  3. C
    Hacktivist threat actor characterized by ideological motivation and desire to cause public operational disruption
  4. D
    Organized crime threat actor characterized by financial extortion motives and deployment of ransomware vectors

Answer

Shadow IT / Non-malicious insider characterized by lack of malicious intent and unauthorized workaround of corporate security controls
The correct answer identifies the individual as a non-malicious insider operating under Shadow IT because the developer is an authorized internal user who deployed unauthorized software solely to complete work duties faster, lacking any hostile or malicious intent.

Step-by-Step Solution

1
Analyze the actor's relationship to the organization and intent
The actor is an internal employee (developer) who had no malicious intent to harm systems or steal data.
Threat actor classification depends heavily on location (internal vs external) and intent (malicious vs non-malicious).
2
Evaluate the attack vector and security control status
The developer installed unapproved software to bypass bandwidth controls to complete job tasks faster.
Deploying unapproved applications or hardware to circumvent security protocols defines Shadow IT.
3
Synthesize the findings to select the correct threat actor profile
The combination of an internal employee, lack of harmful intent, and usage of unapproved software maps precisely to a non-malicious insider utilizing Shadow IT.
This matches standard cybersecurity threat actor attribute definitions.

Key Concept

Threat Actor Attributes and Shadow IT
Estimated Time:1m 15s
Rate this question