A telecommunications enterprise security team detects covert data staging on an internal jump host. The activity was conducted during off-peak hours using valid domain administrative credentials, bypassing perimeter firewalls without triggering external traffic alerts. The entity utilized native system administration tools to clear system logs and pivot into restricted intellectual property repositories. Which TWO of the following threat actor attributes or capabilities are most characteristic of this adversary profile? (Select TWO)
- Pre-existing legitimate authentication credentials and system access permissionsAnswer
- Intimate familiarity with internal organizational workflows, auditing mechanisms, and security controlsAnswer
- CHeavy reliance on automated, mass-scanning exploit kits directed at unpatched perimeter appliances
- DPublic site defacement and service disruption intended to maximize political visibility
Answer
The threat actor profile is characterized by pre-existing legitimate authentication credentials and intimate familiarity with internal organizational workflows and security controls.
The scenario describes an adversary operating from within the network perimeter using valid domain administrator credentials and living-off-the-land techniques (native administration scripts and log suppression). These actions directly reflect an insider threat profile characterized by pre-existing legitimate access permissions and deep familiarity with internal security controls and auditing procedures.
Step-by-Step Solution
Key Concept
Threat Actor Attributes: Insider Threats vs. External Attackers