Soru

Zorluk: OrtaThreat Actors, Attributes, and Attack Vectors

Match each threat actor category with its primary motivation and characteristic attack vector in an enterprise environment.

  • Nation-State Threat ActorMotivated by geopolitical espionage; utilizes supply chain compromises and undisclosed zero-day vulnerabilities for sustained undetected persistence.
  • Organized Crime Threat GroupMotivated by financial profit; leverages stolen third-party credentials to infiltrate networks and deploy extortion software.
  • Shadow IT / Unintentional InsiderMotivated by convenience or work efficiency; introduces vulnerability by integrating unauthorized cloud storage services through direct web browser vectors.
  • Hacktivist CollectiveMotivated by political or social ideology; utilizes high-volume distributed denial-of-service (DDoS) attacks and web application defacement.

Cevap

Nation-State Threat Actor pairs with geopolitical espionage using supply chain compromises and zero-day exploits. Organized Crime Threat Group pairs with financial motivation using stolen credentials for extortion software. Shadow IT / Unintentional Insider pairs with convenience motivation using unauthorized cloud services. Hacktivist Collective pairs with ideological motivation using DDoS and web defacements.
Each threat actor category aligns directly with its characteristic motivation, capability level, and preferred attack vector: Nation-state actors seek geopolitical intelligence via zero-days and supply chain exploits; organized crime seeks financial gain through ransomware and credential theft; shadow IT stems from non-malicious employee convenience via unauthorized SaaS tools; and hacktivists seek publicity for political causes using DDoS and defacement.

Adım Adım Çözüm

1
Identify the primary motivation and sophistication level for each threat actor.
Nation-state actors focus on espionage, organized crime on money, hacktivists on ideology, and shadow IT on convenience.
Threat actor categorization starts by distinguishing core intent and capability bounds.
2
Map each threat actor profile to its matching attack vector and operational objective.
Espionage maps to supply chain/zero-days, financial extortion maps to credential compromise/ransomware, convenience maps to unauthorized cloud/web vectors, and ideological disruption maps to DDoS/defacement.
Attack vectors reflect the resources, persistence requirements, and targets typical of each actor category.

Anahtar Kavram

Threat Actor Profiles, Motivations, and Vectors
Bu soruyu puanla