SY0-701 exam dumps

SY0-701 practice question 53 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 53

Select 2Threat actors: Nation-state , Unskilled attacker , Hacktivist , Insider threat , Organized crime , Shadow IT

A security analyst discovers that several employees have been uploading customer records to a public file-sharing service to collaborate with an external marketing firm. The service was not approved by IT, does not enforce the company's retention requirements, and uses personal employee accounts. During the same week, the company's website is defaced with political messages after a simple password spray attack against a low-privilege web admin account. Which TWO threat actor or activity classifications best match these incidents?

  1. A

    Shadow IT for the file-sharing service use, and hacktivist for the website defacement

  2. B

    Insider threat for the file-sharing service use, and nation-state for the website defacement

  3. C

    Organized crime for the file-sharing service use, and unskilled attacker for the website defacement

  4. D

    Shadow IT for the file-sharing service use, and unskilled attacker for the website defacement

  5. E

    Hacktivist for the file-sharing service use, and insider threat for the website defacement

Show answer and explanation

Correct answers: A, D

Explanation

This scenario intentionally tests the difference between threat actor motivation and organizational risk categories. The unapproved file-sharing platform is a textbook example of shadow IT, a common Security+ concept referring to systems or services used without formal organizational approval, visibility, or governance. This creates data exposure, retention, compliance, and account management risks, especially when personal accounts are involved.

For the website incident, hacktivist is the strongest classification when the attack is used to spread political messages or support a cause. However, the described technique, password spraying followed by simple defacement, is also consistent with an unskilled attacker using basic methods rather than advanced tradecraft. That is why both options 1 and 4 are defensible in this scenario-based context.

From a best-practice perspective, organizations should address shadow IT through acceptable use policies, sanctioned collaboration tools, CASB or SaaS discovery capabilities where applicable, DLP, and security awareness training. To reduce exposure to basic attacks like password spraying, organizations should implement MFA, prohibit weak and reused passwords, monitor authentication logs, and follow hardening guidance such as NIST password and access control recommendations. Relevant references include NIST SP 800-53 for access control and audit controls, NIST SP 800-61 for incident handling, and common identity security guidance for MFA and password attack mitigation.

  • A. Correct.

    Correct. Employees using an unapproved public file-sharing platform for business purposes is a classic example of shadow IT: technology or services deployed or used outside formal IT approval and governance. The website defacement with political messaging strongly aligns with a hacktivist motive, since hacktivists commonly target public-facing sites to promote ideological or political causes. Even though the intrusion used a relatively simple technique, the motive and outcome support the hacktivist classification.

  • B. Incorrect.

    Incorrect. The file-sharing behavior could involve insider risk, but the most precise classification based on the facts is shadow IT because the key issue described is use of an unauthorized service outside IT oversight. The website defacement does not indicate nation-state activity; nation-state actors are typically associated with strategic espionage, long-term persistence, geopolitical objectives, or disruption of critical infrastructure, not simple public defacement with political slogans alone.

  • C. Incorrect.

    Incorrect. There is no indication the file-sharing service use was financially motivated or run by a criminal enterprise, so organized crime is not the best fit. The website attack could have been performed by an unskilled attacker because password spraying is not highly sophisticated, but this option misses the more important attribution clue: the political messages suggest hacktivist motivation rather than merely low skill.

  • D. Correct.

    Correct. The file-sharing service usage is shadow IT because employees adopted an unauthorized cloud service with personal accounts, bypassing company controls. The website attack also plausibly fits an unskilled attacker because password spraying against a low-privilege account and basic defacement are common low-complexity tactics. On Security+ style questions, both motive and capability can be used for classification; here, the technical method supports unskilled attacker even if another option captures the motive.

  • E. Incorrect.

    Incorrect. The file-sharing activity is not hacktivism because there is no ideological or political motivation. The website defacement is also not best classified as an insider threat because the scenario describes an external password spray attack against a web admin account, not misuse by a trusted internal user or someone with authorized access.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam