200-201 Question 27
Single answerA cybersecurity analyst at a SOC has identified suspicious activity indicating a potential data exfiltration attempt. Upon further investigation, they determine the threat actor is financially motivated and uses phishing emails to gain initial access to the network. Based on this information, what type of threat actor is most likely responsible?
- A
Hacktivist
- B
Insider Threat
- C
State-Sponsored Actor
- D
Cybercriminal
Show answer and explanation
Correct answer: D
Explanation
The scenario describes a financially motivated threat actor leveraging phishing emails, which aligns with common tactics used by cybercriminals. Hacktivists, insider threats, and state-sponsored actors have motivations and operational objectives that differ from those described in this case.
- A. Incorrect.
Hacktivists are motivated by political or social causes, not financial gain. This does not align with the financial motive described in the scenario.
- B. Incorrect.
Insider threats are individuals within an organization who intentionally or unintentionally compromise security. There is no indication in the scenario that the threat originated internally.
- C. Incorrect.
State-sponsored actors are typically motivated by espionage, intelligence gathering, or national interests, rather than financial gain. This does not match the scenario.
- D. Correct.
Cybercriminals are financially motivated threat actors who often use tactics like phishing to achieve their goals. This matches the description provided in the scenario.