A regional water treatment utility discovers an advanced network intrusion. Forensic investigators determine that the threat group maintained undetected persistence within the operational technology (OT) network for over nine months. Rather than deploying ransomware or causing immediate service disruption, the group focused exclusively on collecting SCADA configuration files and mapping control system logic. Which TWO of the following threat actor attributes and vector profiles most accurately describe this incident? (Select TWO)
- Nation-state threat actor operating with high sophistication, extensive funding, and geopolitical espionage motives.Cevap
- Supply chain compromise of a trusted third-party software vendor used for remote industrial control maintenance.Cevap
- CHacktivist collective seeking immediate financial profit and public notoriety through automated ransomware deployment.
- DScript kiddie utilizing publicly available automated scanner tools to execute opportunistic distributed denial-of-service (DDoS) attacks.
Cevap
The incident is best characterized by a nation-state threat actor motivated by geopolitical espionage and high-sophistication persistence, along with a supply chain attack vector leveraging trusted third-party software management access.
The scenario describes key indicators of a nation-state actor (Advanced Persistent Threat): high technical sophistication, long-term covert persistence, and strategic reconnaissance against critical infrastructure without financial demands. Furthermore, exploiting trusted third-party maintenance software (supply chain vector) is a primary method for such sophisticated actors to infiltrate air-gapped or segmented industrial control networks.
Adım Adım Çözüm
Anahtar Kavram
Threat Actor Attributes and Attack Vectors