200-201 Question 43
Single answerA SOC analyst is investigating suspicious activity on a company's network. They discover that an attacker has exploited a known vulnerability in an unpatched web server to gain unauthorized access. The attacker then attempts to steal sensitive customer data. Which type of cybersecurity threat does this scenario represent?
- A
Insider Threat
- B
Advanced Persistent Threat (APT)
- C
Exploit-based Attack
- D
Distributed Denial of Service (DDoS)
Show answer and explanation
Correct answer: C
Explanation
The scenario describes an attacker exploiting a known vulnerability in an unpatched web server to gain unauthorized access and steal sensitive data. This aligns with the characteristics of an exploit-based attack, where vulnerabilities are specifically targeted to compromise systems. Other options, such as Insider Threats and DDoS, do not match the described behavior.
- A. Incorrect.
An Insider Threat involves a trusted individual within the organization intentionally or unintentionally causing harm, which is not the case in this scenario.
- B. Incorrect.
An Advanced Persistent Threat (APT) refers to a prolonged and targeted cyberattack typically conducted by well-funded and organized groups. While the scenario involves malicious activity, there is no indication of a prolonged or advanced campaign.
- C. Correct.
An Exploit-based Attack involves the attacker leveraging a vulnerability in a system to gain unauthorized access, which aligns with the described scenario of exploiting a known vulnerability in the web server.
- D. Incorrect.
A Distributed Denial of Service (DDoS) attack involves overwhelming a system with traffic to render it unavailable, which is not related to the activities described in the scenario.