PT0-001 · Question #101
A financial institution is asking a penetration tester to determine if collusion capabilities to produce wire fraud are present. Which of the following threat actors should the penetration tester…
The correct answer is A. Insider threat. Wire fraud collusion requires trusted insiders working together to exploit authorized access, making the insider threat actor the most appropriate model for this assessment.
Question
A financial institution is asking a penetration tester to determine if collusion capabilities to produce wire fraud are present. Which of the following threat actors should the penetration tester portray during the assessment?
Options
- AInsider threat
- BNation state
- CScript kiddie
- DCybercrime organization.
How the community answered
(54 responses)- A94% (51)
- C4% (2)
- D2% (1)
Why each option
Wire fraud collusion requires trusted insiders working together to exploit authorized access, making the insider threat actor the most appropriate model for this assessment.
An insider threat actor represents employees or contractors who abuse legitimate, authorized access to commit crimes such as wire fraud; collusion specifically implies coordination between multiple individuals within the organization who exploit their trusted positions. This model best reflects the scenario of internal actors conspiring to manipulate financial systems, which is the exact capability the penetration tester is asked to assess.
Nation-state actors are motivated by geopolitical goals such as espionage or critical infrastructure disruption, not internal financial collusion schemes.
Script kiddies are low-skill actors relying on pre-built tools and lack the internal access or sophistication required to orchestrate coordinated wire fraud collusion.
Cybercrime organizations typically operate as external threat actors targeting organizations from outside, rather than through insider collusion using legitimate internal access.
Concept tested: Threat actor classification for insider collusion
Source: https://csrc.nist.gov/glossary/term/insider_threat
Topics
Community Discussion
No community discussion yet for this question.