During a comprehensive security audit for a healthcare enterprise, a security analyst identifies several distinct threat profiles and attack vectors. Match each threat actor type or vector on the left with its defining operational attribute or scenario on the right.
- Shadow IT DeploymentIntroduces unvetted SaaS file-sharing tools into organizational workflows without IT department authorization or governance oversight.
- Hacktivist CollectiveCoordinates public website defacements and Distributed Denial-of-Service (DDoS) attacks driven primarily by political or social causes.
- Advanced Persistent Threat (APT)Executes long-term, highly sophisticated cyber espionage campaigns using custom zero-day exploits backed by sovereign state resources.
- Disgruntled Employee (Intentional Insider)Exfiltrates proprietary patient research using legitimate administrative privileges immediately prior to resignation due to a personal grievance.
Answer
Shadow IT Deployment matches introducing unvetted SaaS tools without IT authorization. Hacktivist Collective matches coordinating website defacements and DDoS attacks driven by political causes. Advanced Persistent Threat (APT) matches executing long-term cyber espionage using zero-day exploits and state resources. Disgruntled Employee matches exfiltrating research using legitimate administrative privileges prior to resignation.
Shadow IT is characterized by unauthorized technology adoption (unvetted SaaS). Hacktivists are driven by social or political motives through disruptive acts (defacement/DDoS). APTs possess nation-state backing and high technical sophistication for persistent espionage. Disgruntled employees abuse authorized access for malicious exfiltration prior to departure.
Step-by-Step Solution
Key Concept
Threat Actor Types, Attributes, and Attack Vectors