An enterprise security architecture team at a telecommunications firm is updating their threat landscape documentation. Match each threat actor category on the left with its primary operational attributes, resources, and attack vector characteristics on the right.
- Nation-state / Advanced Persistent Threat (APT)Extremely high sophistication and significant funding; targets high-value intelligence via stealthy zero-day exploits and supply chain compromises.
- Disgruntled InsiderVariable technical skill with existing authorized access; motivated by personal grievances to sabotage systems or exfiltrate sensitive internal data.
- Hacktivist CollectiveModerate sophistication motivated by political or ideological causes; relies on public disruptive attacks like website defacement and distributed denial-of-service (DDoS).
- Shadow ITLow malicious intent; motivated by operational convenience, introducing unvetted cloud software and misconfigured assets outside official security oversight.
Cevap
Nation-state / APT matches with high sophistication, state funding, and supply chain/zero-day vectors. Disgruntled Insider matches with legitimate access, personal motivation, and internal sabotage/exfiltration vectors. Hacktivist Collective matches with ideological motivation and high-visibility DDoS/defacement vectors. Shadow IT matches with operational convenience lacking malicious intent, introducing unvetted assets.
Correctly matching threat actors requires aligning their core motivations, sophistication levels, resource availability, and primary attack mechanisms. Nation-state actors rely on heavy funding and stealth (zero-days/supply chain); insiders leverage authorized access; hacktivists target public visibility for ideological causes; and shadow IT introduces risks unintentionally due to unapproved operational workarounds.
Adım Adım Çözüm
Anahtar Kavram
Threat Actor Classifications, Attributes, and Attack Vector Characteristics