Soru

Zorluk: OrtaThreat Actors, Attributes, and Attack Vectors

A security analyst at an e-commerce firm discovers unauthorized administrative access on an internal transactional database. Investigation reveals that the intruder gained access by compromising an automated software update pipeline managed by an external service contractor trusted by the organization. Which of the following attack vectors was primarily exploited to achieve initial access?

  1. Supply chainCevap
  2. B
    Spear phishing
  3. C
    Direct access
  4. D
    Watering hole

Cevap

Supply chain attack vector
The correct answer is supply chain because the threat actor targeted a third-party vendor's software deployment infrastructure to bypass internal boundary controls through pre-established trust relationships.

Adım Adım Çözüm

1
Analyze the entry path described in the scenario
The intruder gained initial entry through a trusted external contractor's automated software deployment pipeline.
Identifying how the threat actor traversed organizational boundaries determines the attack vector category.
2
Evaluate the vector definitions
Compromising third-party vendor code or deployment mechanisms to breach a target organization is classified as a supply chain attack.
Supply chain vectors exploit implicit trust relationships between organizations and their third-party providers.

Anahtar Kavram

Supply Chain Attack Vectors
Tahmini Süre:1m 15s
Bu soruyu puanla