nerdexam
CompTIA

SY0-301 · Question #423

After analyzing and correlating activity from multiple sensors, the security administrator has determined that a group of very well organized individuals from an enemy country is responsible for…

The correct answer is B. Advanced persistent threat. A well-organized, nation-state-sponsored group conducting sophisticated and targeted long-term attacks is the defining characteristic of an Advanced Persistent Threat.

Threats, vulnerabilities, and mitigations

Question

After analyzing and correlating activity from multiple sensors, the security administrator has determined that a group of very well organized individuals from an enemy country is responsible for various attempts to breach the company network, through the use of very sophisticated and targeted attacks. Which of the following is this an example of?

Options

  • APrivilege escalation
  • BAdvanced persistent threat
  • CMalicious insider threat
  • DSpear phishing

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    93% (26)
  • C
    4% (1)

Why each option

A well-organized, nation-state-sponsored group conducting sophisticated and targeted long-term attacks is the defining characteristic of an Advanced Persistent Threat.

APrivilege escalation

Privilege escalation is a specific attack technique used to gain elevated permissions on a system, not a classification of a threat actor or campaign.

BAdvanced persistent threatCorrect

An Advanced Persistent Threat (APT) is characterized by a highly skilled, often state-sponsored adversary that uses sophisticated, targeted techniques to gain and maintain unauthorized access over an extended period. The combination of organizational sophistication, national affiliation, and targeted attack methodology precisely matches the APT definition.

CMalicious insider threat

A malicious insider threat originates from within the organization such as a disgruntled employee, not from an external nation-state group.

DSpear phishing

Spear phishing is a targeted email-based social engineering tactic and represents only one possible technique an APT might use, not the overall threat classification.

Concept tested: Advanced Persistent Threat actor classification

Source: https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats

Topics

#APT#nation-state threats#targeted attacks#threat actors

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice