SY0-701 exam dumps

SY0-701 practice question 56 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 56

Single answerAttributes of actors: Internal/external , Resources/funding , Level of sophistication/capability

A security analyst is reviewing a recent breach at a manufacturing company. The attacker used valid VPN credentials belonging to a current engineer, accessed internal file shares during normal business hours, and copied design documents to a personal cloud storage account over several weeks. There is no evidence of custom malware, zero-day exploitation, or expensive infrastructure; the activity relied mostly on built-in administrative tools and knowledge of where sensitive files were stored. Which assessment best describes the most likely threat actor based on attributes of actor type, resources/funding, and level of sophistication/capability?

  1. A

    An internal actor with limited resources/funding and moderate capability

  2. B

    An external hacktivist with substantial funding and advanced capability

  3. C

    A nation-state actor with extensive resources and highly sophisticated capability

  4. D

    An organized crime group with moderate funding and advanced malware development capability

Show answer and explanation

Correct answer: A

Explanation

This question tests how to classify threat actors using three core attributes emphasized in Security+ objectives: whether the actor is internal or external, the level of resources/funding available, and the actor's sophistication/capability. In this case, the strongest indicators are insider access patterns: valid employee credentials, knowledge of internal file locations, use of normal business hours, and living-off-the-land techniques rather than specialized tooling. Those details support an internal actor assessment. The absence of zero-days, custom malware, or dedicated infrastructure argues against a highly funded, highly sophisticated actor such as a nation-state. CompTIA Security+ commonly expects candidates to distinguish insider threats from external threats by behavioral indicators and to avoid overestimating an actor's sophistication just because data theft was successful. This aligns with standard industry guidance such as NIST insider threat discussions, which note that legitimate access, familiarity with business processes, and misuse of authorized tools are common characteristics of insider activity.

  • A. Correct.

    Correct. The scenario points to an internal actor because the attacker used a current engineer's valid credentials, knew where sensitive design documents were stored, and operated during normal business hours in a way that blends with legitimate activity. The lack of custom malware, zero-day techniques, or costly infrastructure suggests limited resources/funding. However, the actor still demonstrated more than basic skill by abusing legitimate access, using built-in tools, and staging slow data theft over time, which aligns with moderate capability rather than highly advanced tradecraft.

  • B. Incorrect.

    Incorrect. Hacktivists are typically external actors motivated by ideology or publicity, often seeking website defacement, disruption, or public data leaks. The scenario instead shows insider-style behavior: use of a current employee account, familiarity with internal data locations, and quiet exfiltration over weeks. There is also nothing indicating substantial funding or advanced techniques.

  • C. Incorrect.

    Incorrect. Nation-state actors generally have extensive resources and may employ stealthy persistence, custom tooling, supply-chain compromise, or zero-day exploits when targeting valuable intellectual property. While design documents could interest a nation-state, the observed methods here are much simpler and more consistent with insider misuse or compromised insider access than with highly sophisticated state-sponsored operations.

  • D. Incorrect.

    Incorrect. Organized crime groups often pursue direct financial gain through ransomware, payment fraud, business email compromise, or resale of stolen data. They may have moderate funding, but this scenario lacks signs of advanced malware development or external criminal infrastructure. The reliance on valid internal credentials, built-in tools, and insider knowledge makes an internal actor the stronger assessment.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam