SY0-701 exam dumps

SY0-701 practice question 54 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 54

Single answerThreat actors: Nation-state , Unskilled attacker , Hacktivist , Insider threat , Organized crime , Shadow IT

A financial services company discovers that several employees have been using an unsanctioned file-sharing website to exchange customer reports with external partners because the approved secure portal is considered too slow. During the investigation, the security team finds no evidence of malware, ransom notes, privilege escalation, or data theft by outsiders. Management wants to classify the most likely threat actor involved so it can choose the most appropriate response. Which of the following best describes this situation?

  1. A

    Nation-state

  2. B

    Insider threat

  3. C

    Organized crime

  4. D

    Hacktivist

  5. E

    Unskilled attacker

  6. F

    Shadow IT

Show answer and explanation

Correct answer: F

Explanation

The best answer is Shadow IT because the core issue is the use of an unapproved service outside the organization's security and governance controls. In real environments, shadow IT often emerges when employees believe sanctioned tools are too slow or cumbersome. This behavior can expose regulated data, bypass logging and retention controls, and create compliance issues, especially in financial services. Although insiders are involved, Security+ distinguishes between a general insider threat and shadow IT; the latter is the more precise classification when employees adopt unauthorized technology to perform work. A security team should respond by identifying the data exposed, assessing third-party risk, reviewing access logs, blocking or restricting unsanctioned services where appropriate, and improving the approved solution so users are less likely to circumvent it. This aligns with common guidance from NIST cybersecurity practices on asset management, data security, and governance, including maintaining approved technology inventories and enforcing least functionality and approved data-handling processes.

  • A. Incorrect.

    This is incorrect. Nation-state actors are typically well-funded, highly capable adversaries conducting espionage, disruption, or strategic attacks aligned with national objectives. The scenario describes employees bypassing approved processes for convenience, not a coordinated government-backed intrusion or intelligence-gathering campaign.

  • B. Incorrect.

    This is plausible but not the best answer. An insider threat involves a trusted individual who intentionally or negligently misuses authorized access to harm the organization. While employees are involved here, the scenario specifically emphasizes the use of unsanctioned technology outside approved governance. On Security+ objectives, that is more precisely classified as shadow IT unless there is evidence of malicious intent or broader insider abuse.

  • C. Incorrect.

    This is incorrect. Organized crime typically seeks financial gain through fraud, extortion, ransomware, payment card theft, or other monetizable attacks. The scenario contains no indication of criminal monetization, extortion, or an external criminal group operating against the company.

  • D. Incorrect.

    This is incorrect. Hacktivists are ideologically motivated and commonly target organizations to promote a social or political cause, often through defacement, leaks, or service disruption. There is no evidence of political motivation, public messaging, or protest activity in this case.

  • E. Incorrect.

    This is incorrect. An unskilled attacker, sometimes called a script kiddie, usually relies on readily available tools with limited understanding. The scenario does not describe an external attacker attempting exploitation; it describes internal users adopting an unapproved service for business convenience.

  • F. Correct.

    This is correct. Shadow IT refers to systems, applications, or services used without formal approval from the organization's IT or security team. The employees selected an unsanctioned file-sharing platform because the approved option was inconvenient. That creates security and compliance risk even when there is no clear malicious intent.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam