200-201 · Question #403
What is a threat actor?
The correct answer is C. an individual or group that is external or internal and may include nation-states, hacktivists. A threat actor is any individual or group, internal or external, that poses a potential risk to an organization's security, encompassing a wide range of motivations and capabilities.
Question
What is a threat actor?
Options
- Aan external party, typically a business partner with the capability to accidentally or intentionally
- Ban internal individual, typically an insider with the capability to accidentally or intentionally
- Can individual or group that is external or internal and may include nation-states, hacktivists,
- Dan unauthorized person, such as script kiddies or hackers who attempt to breach network
How the community answered
(33 responses)- A3% (1)
- B3% (1)
- C88% (29)
- D6% (2)
Why each option
A threat actor is any individual or group, internal or external, that poses a potential risk to an organization's security, encompassing a wide range of motivations and capabilities.
This definition is too narrow, specifically limiting to external business partners and not covering the full scope of threat actors.
This definition is also too narrow, focusing only on internal individuals (insiders) and excluding external threat actors.
A threat actor is a broad term encompassing any individual or group, whether internal or external to an organization, who has the intent and capability to cause harm to an information system or organization. This includes state-sponsored groups, organized crime, hacktivists, insider threats, and even script kiddies, covering a full spectrum of adversaries.
This definition is too restrictive by only including 'unauthorized persons' like script kiddies or hackers, omitting authorized insiders who become threats, and also nation-states or organized crime.
Concept tested: Definition of a threat actor
Source: https://learn.microsoft.com/en-us/azure/sentinel/understanding-threat-actors
Topics
Community Discussion
No community discussion yet for this question.