During an investigation at a regional power grid operator, incident responders uncover an adversary that maintained persistent, undetected access across internal control networks for over nine months. The adversary utilized customized living-off-the-land techniques to exfiltrate SCADA architecture diagrams and operational telemetry while intentionally avoiding ransomware deployment or disruptive activity. Which of the following threat actor types and attribute profiles best aligns with this behavior?
- Nation-state threat actor characterized by high sophistication, long-term strategic motivation, and extensive resource funding.Cevap
- BHacktivist group characterized by moderate technical skill, ideological motivation, and a focus on public disruption.
- COrganized crime syndicate characterized by financial motivation, rapid monetization tactics, and ransomware delivery vectors.
- DInsider threat characterized by unauthorized Shadow IT deployment intended to bypass administrative controls for convenience.
Cevap
Nation-state threat actor characterized by high sophistication, long-term strategic motivation, and extensive resource funding.
The correct option correctly attributes the threat activity to a nation-state actor. Prolonged, covert access combined with sophisticated living-off-the-land techniques and targeted exfiltration of critical infrastructure telemetry indicates a well-funded, highly sophisticated threat actor motivated by strategic intelligence gathering.
Adım Adım Çözüm
Anahtar Kavram
Threat Actor Attributes and Intent Alignment
Tahmini Süre:1m 30s