Question

Difficulty: HardThreat Actors, Attributes, and Attack Vectors

A telecommunications enterprise security team detects covert data staging on an internal jump host. The activity was conducted during off-peak hours using valid domain administrative credentials, bypassing perimeter firewalls without triggering external traffic alerts. The entity utilized native system administration tools to clear system logs and pivot into restricted intellectual property repositories. Which TWO of the following threat actor attributes or capabilities are most characteristic of this adversary profile? (Select TWO)

  1. Pre-existing legitimate authentication credentials and system access permissionsAnswer
  2. Intimate familiarity with internal organizational workflows, auditing mechanisms, and security controlsAnswer
  3. C
    Heavy reliance on automated, mass-scanning exploit kits directed at unpatched perimeter appliances
  4. D
    Public site defacement and service disruption intended to maximize political visibility

Answer

The threat actor profile is characterized by pre-existing legitimate authentication credentials and intimate familiarity with internal organizational workflows and security controls.
The scenario describes an adversary operating from within the network perimeter using valid domain administrator credentials and living-off-the-land techniques (native administration scripts and log suppression). These actions directly reflect an insider threat profile characterized by pre-existing legitimate access permissions and deep familiarity with internal security controls and auditing procedures.

Step-by-Step Solution

1
Analyze the attack indicators and operational tactics described in the scenario.
The adversary leveraged valid domain administrator accounts, operated during off-peak hours, used built-in administrative tools, cleared local audit logs, and avoided perimeter detection.
Identifying specific behavioral patterns allows analysts to differentiate between external opportunistic attackers and malicious insiders or advanced persistent threats.
2
Match the observed tactics to threat actor attributes.
Using valid internal credentials demonstrates pre-existing legitimate access, while clearing logs with internal utilities demonstrates detailed knowledge of environment defenses.
Insider threats possess innate privileges and operational familiarity that enable them to bypass standard perimeter security controls seamlessly.

Key Concept

Threat Actor Attributes: Insider Threats vs. External Attackers
Rate this question