Soru

Zorluk: Çok zorThreat Actors, Attributes, and Attack Vectors

An incident response team investigating a breach at a regional cloud healthcare provider discovers that infrastructure automation scripts were modified to disable TLS verification across internal microservices. Forensic analysis shows the modification was performed using an active API token originally issued to a former system Administrator who recently left the organization on poor terms. Although the connection originated from an anonymized VPN node commonly associated with political hacktivist campaigns, no external software vulnerabilities or social engineering attacks were involved. Which threat actor type and attack vector combination primary characterizes this incident?

  1. Insider threat utilizing a direct credential access vectorCevap
  2. B
    Hacktivist collective utilizing a social engineering vector
  3. C
    Nation-state threat actor utilizing an upstream supply chain vector
  4. D
    Shadow IT operator utilizing an unpatched perimeter vulnerability vector

Cevap

An insider threat utilizing a direct credential access vector best characterizes the incident.
An insider threat includes current or former employees who retain authentic credentials or possess inside knowledge of infrastructure operations. Because the attack utilized legitimate API keys previously assigned to an offboarded administrator, the primary threat actor classification is an insider threat, and the attack vector is direct credential abuse.

Adım Adım Çözüm

1
Analyze the threat actor attributes
The perpetrator is a former employee possessing inside knowledge and pre-existing valid access keys.
Threat actors with current or retained authorized access fall under the insider threat classification, regardless of post-employment political affiliations or routing proxies.
2
Analyze the attack vector
The intrusion relied on valid API tokens directly authenticating to administrative services.
Direct credential access via orphaned or un-revoked keys constitutes a direct administrative vector rather than social engineering, malware, or exploit-based vectors.

Anahtar Kavram

Threat Actor Classification and Attack Vector Identification
Tahmini Süre:2m 30s
Bu soruyu puanla