A cybersecurity analyst is conducting a threat model assessment for a renewable energy infrastructure firm. The analyst needs to accurately map different threat actor categories to their characteristic attributes, motivations, and attack vectors. Which of the following statements correctly align a threat actor category with its defining attributes and attack vectors? (Select TWO).
- Hacktivist groups are driven by political or ideological motivations and typically employ attack vectors such as web defacement and distributed denial-of-service (DDoS) attacks to gain publicity.Answer
- BScript kiddies possess high technical sophistication and primarily develop custom zero-day exploits to execute supply chain attacks against defense contractors.
- Insider threats possess legitimate organizational credentials or physical access, allowing them to bypass traditional perimeter security controls without launching external penetration vectors.Answer
- DShadow IT actors are state-sponsored operatives who utilize covert persistence techniques to exfiltrate intellectual property for geopolitical advantage.
Answer
Hacktivist groups are driven by political or ideological motivations and typically employ attack vectors such as web defacement and distributed denial-of-service (DDoS) attacks to gain publicity. Insider threats possess legitimate organizational credentials or physical access, allowing them to bypass traditional perimeter security controls without launching external penetration vectors.
The correct choices accurately describe hacktivists (driven by ideology and public disruption tactics like DDoS) and insider threats (leveraging existing legitimate access to bypass perimeter defenses).
Step-by-Step Solution
Key Concept
Threat Actor Attributes, Motivations, and Attack Vectors