nerdexam
EC-Council

112-52 · Question #72

Which of the following best defines a 'threat actor'?

The correct answer is B. An entity that has the potential to cause harm by exploiting a vulnerability. Option B is correct because a threat actor is defined by who or what is doing the threatening - it refers to any entity (person, group, nation-state, or even an insider) capable of intentionally or unintentionally exploiting a vulnerability to cause harm. A is wrong because it…

Ethical Hacking Fundamentals

Question

Which of the following best defines a 'threat actor'?

Options

  • AA software that poses a threat to information security
  • BAn entity that has the potential to cause harm by exploiting a vulnerability
  • CThe method by which a threat is delivered
  • DA tool used to assess the level of threat on a network

How the community answered

(22 responses)
  • B
    91% (20)
  • C
    5% (1)
  • D
    5% (1)

Explanation

Option B is correct because a threat actor is defined by who or what is doing the threatening - it refers to any entity (person, group, nation-state, or even an insider) capable of intentionally or unintentionally exploiting a vulnerability to cause harm.

  • A is wrong because it describes malware or malicious software, not the actor behind a threat.
  • C is wrong because it describes an attack vector - the pathway or method used to deliver a threat.
  • D is wrong because it describes a vulnerability scanner or threat assessment tool, which is an instrument used defensively.

Memory tip: Think of "actor" the way you would in a play - an actor is a person or entity performing an action. A threat actor performs the threat; they are not the weapon, the method, or the measuring tool.

Topics

#Threat Actor#Vulnerability Exploitation#Security Fundamentals#Risk Assessment

Community Discussion

No community discussion yet for this question.

Full 112-52 Practice