SY0-701 exam dumps

SY0-701 practice question 55 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 55

Single answerAttributes of actors: Internal/external , Resources/funding , Level of sophistication/capability

A financial services company discovers unusual outbound traffic from a database server that contains merger-related documents. The activity began shortly after a senior analyst was placed on a performance improvement plan. Investigation shows the analyst used valid credentials to access the files after hours, compressed them with a common archiving tool, and uploaded them to a personal cloud storage account. There is no evidence of custom malware, privilege escalation, or attempts to bypass technical controls. Which threat actor assessment is MOST accurate based on the available evidence?

  1. A

    An internal actor with limited resources and moderate capability, using authorized access to exfiltrate data

  2. B

    An external nation-state actor with extensive funding and advanced capability, conducting a long-term espionage campaign

  3. C

    An external hacktivist group with moderate funding and low capability, disrupting operations for publicity

  4. D

    An internal organized crime actor with significant funding and advanced capability, deploying custom tooling to evade detection

Show answer and explanation

Correct answer: A

Explanation

This question tests the ability to classify threat actors by internal versus external origin, available resources/funding, and level of sophistication/capability. The strongest indicators here are the use of valid employee credentials, authorized access to the target data, and simple exfiltration techniques with common tools. Those facts align with an insider threat rather than an external attacker. In Security+ terms, insider threats can include employees, contractors, or partners who misuse legitimate access. Their capability may be moderate even when their resources are limited, because authorized access reduces the need for advanced exploitation. Best-practice guidance from sources such as NIST emphasizes evaluating threat actors by intent, access, capability, and opportunity. The absence of custom malware, privilege escalation, persistence, or stealth techniques makes high-resource, highly sophisticated actor categories much less likely.

  • A. Correct.

    Correct. The scenario points to an internal actor because the activity was performed by an employee using valid credentials and legitimate access to sensitive data. The methods used, after-hours access, file compression, and upload to personal cloud storage, indicate practical but not highly advanced tradecraft. There is no sign of custom malware, stealthy persistence, or sophisticated evasion, so the most accurate characterization is limited resources with moderate capability.

  • B. Incorrect.

    Incorrect. A nation-state actor is typically associated with substantial funding, high sophistication, and more advanced tradecraft such as stealth, persistence, specialized tooling, or covert command-and-control. In this case, the actor used a straightforward insider method with valid credentials and common tools, which does not support an external advanced persistent threat assessment.

  • C. Incorrect.

    Incorrect. Hacktivists are generally motivated by ideology, publicity, or disruption rather than theft of merger documents for personal or financial reasons. The evidence also does not suggest an external actor, since the activity was tied to a named employee using legitimate access. This option confuses motivation and actor location.

  • D. Incorrect.

    Incorrect. While organized crime can be well funded and focused on data theft for profit, the scenario does not show hallmarks of a well-resourced criminal operation, such as specialized malware, coordinated fraud infrastructure, or advanced evasion. It also incorrectly implies custom tooling was used, which directly contradicts the facts presented.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam