nerdexam
CompTIA

PT0-001 · Question #101

A financial institution is asking a penetration tester to determine if collusion capabilities to produce wire fraud are present. Which of the following threat actors should the penetration tester…

The correct answer is A. Insider threat. Wire fraud collusion requires trusted insiders working together to exploit authorized access, making the insider threat actor the most appropriate model for this assessment.

Engagement management

Question

A financial institution is asking a penetration tester to determine if collusion capabilities to produce wire fraud are present. Which of the following threat actors should the penetration tester portray during the assessment?

Options

  • AInsider threat
  • BNation state
  • CScript kiddie
  • DCybercrime organization.

How the community answered

(54 responses)
  • A
    94% (51)
  • C
    4% (2)
  • D
    2% (1)

Why each option

Wire fraud collusion requires trusted insiders working together to exploit authorized access, making the insider threat actor the most appropriate model for this assessment.

AInsider threatCorrect

An insider threat actor represents employees or contractors who abuse legitimate, authorized access to commit crimes such as wire fraud; collusion specifically implies coordination between multiple individuals within the organization who exploit their trusted positions. This model best reflects the scenario of internal actors conspiring to manipulate financial systems, which is the exact capability the penetration tester is asked to assess.

BNation state

Nation-state actors are motivated by geopolitical goals such as espionage or critical infrastructure disruption, not internal financial collusion schemes.

CScript kiddie

Script kiddies are low-skill actors relying on pre-built tools and lack the internal access or sophistication required to orchestrate coordinated wire fraud collusion.

DCybercrime organization.

Cybercrime organizations typically operate as external threat actors targeting organizations from outside, rather than through insider collusion using legitimate internal access.

Concept tested: Threat actor classification for insider collusion

Source: https://csrc.nist.gov/glossary/term/insider_threat

Topics

#threat actors#insider threat#wire fraud#assessment scoping

Community Discussion

No community discussion yet for this question.

Full PT0-001 Practice