SY0-701 exam dumps

SY0-701 practice question 52 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 52

Single answer2.1 Compare and contrast common threat actors and motivations.

A regional electric utility discovers that several engineering workstations in its operational technology (OT) network were compromised after employees received highly tailored emails containing malicious attachments. The malware remained dormant for weeks, exfiltrated network diagrams and PLC configuration files, and attempted to establish persistent access without immediately encrypting systems or demanding payment. Threat intelligence shows the infrastructure and tactics overlap with campaigns previously linked to a foreign government. Which threat actor is MOST likely responsible for this activity?

  1. A

    Organized crime seeking direct financial gain through ransomware

  2. B

    Nation-state actor conducting espionage and preparing for possible future disruption

  3. C

    Script kiddie experimenting with publicly available tools for notoriety

  4. D

    Insider threat motivated by revenge against management

Show answer and explanation

Correct answer: B

Explanation

The best answer is nation-state actor conducting espionage and preparing for possible future disruption. Security+ expects candidates to distinguish threat actors by capability, targeting, and motivation. Nation-state actors commonly target critical infrastructure, defense, telecommunications, and energy sectors for intelligence gathering, strategic advantage, or pre-positioning within key systems. The use of spearphishing, long-term persistence, stealth, and theft of industrial control information are classic indicators of espionage-oriented operations rather than quick financial crime. This aligns with widely recognized guidance from CISA, NIST, and joint government advisories that describe advanced persistent threat behavior in critical infrastructure environments, especially when adversaries seek to maintain access and collect operationally significant data instead of immediately monetizing the intrusion.

  • A. Incorrect.

    This is incorrect. Organized criminal groups are commonly motivated by profit and often use ransomware, business email compromise, credential theft, or payment card theft to monetize access quickly. In this scenario, there is no ransom demand or immediate financial objective. The focus on long-term persistence, theft of OT network diagrams, and overlap with government-linked campaigns points away from financially motivated cybercrime.

  • B. Correct.

    This is correct. The scenario aligns strongly with a nation-state or advanced persistent threat (APT) actor. Indicators include strategic targeting of critical infrastructure, highly tailored spearphishing, stealthy long dwell time, exfiltration of sensitive engineering and PLC configuration data, and establishment of persistence for potential future operations. Nation-state actors are often motivated by espionage, geopolitical advantage, intelligence collection, or pre-positioning for disruption during a conflict.

  • C. Incorrect.

    This is incorrect. Script kiddies typically rely on readily available tools and generally lack the resources, patience, and operational discipline demonstrated here. The tailored phishing, delayed execution, stealthy persistence, and interest in OT-specific information are far more sophisticated than the behavior usually associated with inexperienced attackers seeking attention or basic experimentation.

  • D. Incorrect.

    This is incorrect. An insider threat could have access to sensitive systems, but the scenario specifically highlights external phishing, malware delivery, and infrastructure linked to previous foreign-government campaigns. While insiders can be motivated by revenge, the evidence provided more strongly supports an external, well-resourced adversary rather than a disgruntled employee.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam