200-201 Question 44
Single answerA company's security operations center (SOC) has detected a suspicious file being downloaded from an external website by an employee. Upon further investigation, the file is identified as malware designed to exfiltrate sensitive data. What type of threat does this situation represent?
- A
Insider threat
- B
Advanced persistent threat (APT)
- C
Social engineering attack
- D
Malware-based threat
Show answer and explanation
Correct answer: D
Explanation
The correct answer is 'Malware-based threat' because the scenario explicitly describes a malicious file that is downloaded and designed to extract sensitive information. While other options such as insider threats, APTs, or social engineering could be relevant in different contexts, the primary focus here is on the malware itself as the vehicle for the threat.
- A. Incorrect.
Insider threat refers to malicious actions carried out by trusted individuals within an organization, such as employees or contractors. In this case, the threat originates from an external file, not an insider.
- B. Incorrect.
Advanced persistent threats (APTs) are prolonged, targeted cyberattacks often conducted by nation-states or organized groups. While this attack could be part of an APT campaign, the scenario specifically highlights a malware-based threat, not the extended and targeted characteristics of an APT.
- C. Incorrect.
Social engineering attacks focus on manipulating human behavior to gain unauthorized access or information. While the employee may have been tricked into downloading the file, the focus here is on the malicious file itself, which is malware.
- D. Correct.
Malware-based threat is the correct answer because the situation involves a malicious file designed to exfiltrate sensitive data, which directly aligns with the definition of a malware-based threat.