112-52 · Question #72
Which of the following best defines a 'threat actor'?
The correct answer is B. An entity that has the potential to cause harm by exploiting a vulnerability. Option B is correct because a threat actor is defined by who or what is doing the threatening - it refers to any entity (person, group, nation-state, or even an insider) capable of intentionally or unintentionally exploiting a vulnerability to cause harm. A is wrong because it…
Question
Which of the following best defines a 'threat actor'?
Options
- AA software that poses a threat to information security
- BAn entity that has the potential to cause harm by exploiting a vulnerability
- CThe method by which a threat is delivered
- DA tool used to assess the level of threat on a network
How the community answered
(22 responses)- B91% (20)
- C5% (1)
- D5% (1)
Explanation
Option B is correct because a threat actor is defined by who or what is doing the threatening - it refers to any entity (person, group, nation-state, or even an insider) capable of intentionally or unintentionally exploiting a vulnerability to cause harm.
- A is wrong because it describes malware or malicious software, not the actor behind a threat.
- C is wrong because it describes an attack vector - the pathway or method used to deliver a threat.
- D is wrong because it describes a vulnerability scanner or threat assessment tool, which is an instrument used defensively.
Memory tip: Think of "actor" the way you would in a play - an actor is a person or entity performing an action. A threat actor performs the threat; they are not the weapon, the method, or the measuring tool.
Topics
Community Discussion
No community discussion yet for this question.