nerdexam
Cisco

100-160 · Question #34

Drag and Drop Question Move each scenario from the list on the left to the correct type of attacker on the right. Note: You will receive partial credit for each correct answer. Answer:

The correct answer is Tries to profit from personal data gained by spamming companies or individuals; Interferes in a government election to promote its agenda; Hires an external contractor who installs malware on a server; Attacker has a personal ambition to promote a self-defined sense of justice. Drag-and-Drop: Matching Scenarios to Attacker Types This question maps attacker behaviors to four standard threat actor categories. The four positions correspond to these attacker types (in order): | Position | Attacker Type | |----------|---------------| | 1 | Cybercriminal /…

Threats and Vulnerabilities

Question

Drag and Drop Question Move each scenario from the list on the left to the correct type of attacker on the right. Note: You will receive partial credit for each correct answer. Answer:

Exhibit

100-160 question #34 exhibit

Answer Area

Drag items

Interferes in a government election to promote its agendaHires an external contractor who installs malware on a serverTries to profit from personal data gained by spamming companies or individualsAttacker has a personal ambition to promote a self-defined sense of justiceAttempts to steal financial information by spamming companies or individuals

Correct arrangement

  • Tries to profit from personal data gained by spamming companies or individuals
  • Interferes in a government election to promote its agenda
  • Hires an external contractor who installs malware on a server
  • Attacker has a personal ambition to promote a self-defined sense of justice

Explanation

Drag-and-Drop: Matching Scenarios to Attacker Types

This question maps attacker behaviors to four standard threat actor categories. The four positions correspond to these attacker types (in order):

PositionAttacker Type
1Cybercriminal / Organized Crime
2Nation-State / State-Sponsored Actor
3Insider Threat
4Hacktivist

Item-by-Item Breakdown

Position 1 - "Tries to profit from personal data gained by spamming" → Cybercriminal Cybercriminals are financially motivated. Monetizing stolen personal data (selling PII, identity theft) via spam campaigns is a textbook cybercriminal behavior. The key signal is profit motive.

Position 2 - "Interferes in a government election to promote its agenda" → Nation-State Actor Nation-state attackers are politically or ideologically motivated governments or state-sponsored groups. Election interference to advance a political agenda is the defining behavior of state-sponsored APTs.

Position 3 - "Hires an external contractor who installs malware" → Insider Threat The contractor gains trusted access to internal systems - that's what makes this an insider threat. The threat doesn't have to be a direct employee; third-party vendors and contractors with privileged access are a classic insider threat vector (also called a supply-chain insider threat).

Position 4 - "Personal ambition to promote a self-defined sense of justice" → Hacktivist Hacktivists are driven by ideology or a personal moral code, not money. The phrase "self-defined sense of justice" is the precise marker - they attack to make a statement or right a perceived wrong.


The Distractor - "Attempts to steal financial information by spamming"

This item is not placed in the correct arrangement. It's a deliberate distractor designed to confuse you with Position 1. Here's the distinction:

  • Placed (Position 1): Profits from personal data (PII, identity theft pipeline)
  • Distractor: Steals financial information (credentials, card numbers)

Both look like cybercriminals, but only one matched the category as defined in this question's answer key. On the real exam, read carefully - "personal data" vs. "financial information" is the differentiator.


Common Misconceptions

  • Insider threat ≠ malicious employee only. Contractors, vendors, and any trusted third party count. The malware-installing contractor is a classic trap.
  • Hacktivists vs. Nation-states: Both can have ideological motives, but nation-states act on behalf of a government's geopolitical agenda (election interference), while hacktivists act on personal/group moral conviction.
  • Don't confuse cybercriminals with all financially motivated actors - organized crime groups, ransomware gangs, and spam operations all fall here.

Topics

#threat actors#attacker types#insider threat#nation-state

Community Discussion

No community discussion yet for this question.

Full 100-160 Practice