SY0-701 Question 57
Single answerA defense contractor discovers that an engineer who recently resigned copied proprietary drone design files to a personal cloud storage account over several weeks. At the same time, investigators find encrypted email exchanges between the engineer and a foreign technology firm. There is no evidence that the engineer deployed malware or tried to disrupt operations, but the stolen files include export-controlled technical data and internal pricing models. Which motivation BEST explains this activity?
- A
Service disruption
- B
Espionage
- C
Ethical
- D
Philosophical/political beliefs
- E
Revenge
Show answer and explanation
Correct answer: B
Explanation
The best answer is espionage because the central facts are unauthorized data exfiltration of sensitive technical information and contact with a foreign organization, suggesting intelligence collection or competitive theft rather than disruption, ethics, ideology, or personal retaliation. Security+ expects candidates to distinguish motivations based on indicators in the scenario: exfiltration of intellectual property and restricted data points to espionage, while outages point to service disruption, public-cause messaging points to philosophical or political beliefs, and retaliatory sabotage points to revenge. This aligns with common guidance in insider threat and data protection programs, including principles reflected in NIST insider threat and incident handling practices, where motive assessment considers what was taken, who received it, and whether the actor sought profit, advantage, publicity, or operational impact.
- A. Incorrect.
This is incorrect because the scenario does not describe attempts to interrupt availability, degrade services, or deny access to systems. Service disruption is associated with attacks such as DDoS, sabotage of infrastructure, or operational outages, none of which are present here.
- B. Correct.
This is correct because the engineer exfiltrated sensitive proprietary and export-controlled information and communicated with a foreign technology firm, indicating theft of valuable information for strategic or competitive advantage. In Security+ terms, espionage commonly involves unauthorized acquisition of intellectual property, trade secrets, or national-security-related data on behalf of a competitor or nation-state.
- C. Incorrect.
This is incorrect because ethical motivation is associated with authorized or sanctioned security testing, such as work by internal security staff or contracted penetration testers operating with permission and defined scope. Here, the engineer resigned, copied data to a personal account, and shared it externally without authorization.
- D. Incorrect.
This is incorrect because although political or ideological beliefs can motivate insider theft or leaks, the scenario more strongly points to intelligence gathering or competitive theft due to the foreign firm communications and the nature of the stolen data. There is no indication the engineer was attempting to make a political statement or expose wrongdoing publicly.
- E. Incorrect.
This is incorrect because revenge is a plausible insider motive when a disgruntled employee deletes data, leaks embarrassing records, or damages systems after conflict with the employer. However, the facts here focus on covert transfer of technical and pricing information to an outside foreign entity, which aligns more directly with espionage than retaliatory harm.