CompTIA Security+ SY0-701 Threat Actors and Motivations Practice Test 1

 

Topic 05 Practice Test 1 covers Threat Actors and Motivations for CompTIA Security+ SY0-701 and maps to objective 2.1: Compare and contrast common threat actors and motivations. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

To steal funds, commit fraud, demand ransom, or sell access and data, which security approach should be selected?

  1. War motivation
  2. Nation-state threat actor
  3. Financial gain motivation
  4. Blackmail motivation

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Financial gain motivation means a goal of directly or indirectly obtaining money. That is the function the question is testing. Blackmail motivation would instead be used for a goal of coercing a victim by threatening disclosure, damage, or other harmful action.

Incorrect Answers

 

Answer A is incorrect because War motivation refers to a goal connected to military or geopolitical conflict. That concept can be valid in another scenario, but this question is testing a goal of directly or indirectly obtaining money; Financial gain motivation therefore fits the requirement more directly.

Answer B is incorrect because Nation-state threat actor refers to a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives. The scenario instead requires a goal of directly or indirectly obtaining money, which is why Financial gain motivation is the better answer; this option serves the different function defined above.

Answer D is incorrect because Blackmail motivation refers to a goal of coercing a victim by threatening disclosure, damage, or other harmful action. The key mismatch is functional: Financial gain motivation addresses a goal of directly or indirectly obtaining money, the need stated by the question.

 

Question 2

To target organizations because of what they represent or support, which security approach should be selected?

  1. Hacktivist
  2. Nation-state threat actor
  3. Data exfiltration motivation
  4. Ideological motivation

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Ideological motivation means a goal driven by philosophical, political, or social beliefs. The requirement maps directly to this function, whereas Nation-state threat actor is aimed at a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives.

Incorrect Answers

 

Answer A is incorrect because Hacktivist refers to an attacker motivated primarily by political, social, or ideological goals. The question is not asking for this function. It is testing a goal driven by philosophical, political, or social beliefs, so Ideological motivation is the stronger fit.

Answer B is incorrect because Nation-state threat actor refers to a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives. The key mismatch is functional: Ideological motivation addresses a goal driven by philosophical, political, or social beliefs, the need stated by the question.

Answer C is incorrect because Data exfiltration motivation refers to a goal centered on stealing information from the target environment. The scenario instead requires a goal driven by philosophical, political, or social beliefs, which is why Ideological motivation is the better answer; this option serves the different function defined above.

 

Question 3

The control set for a threat-intelligence assessment must address both person with legitimate internal access who causes harm intentionally or accidentally and goal driven by philosophical, political, or social beliefs. Which TWO choices map directly to those needs? Choose TWO.

  1. Organized crime
  2. Insider threat
  3. Ideological motivation
  4. Financial gain motivation
  5. Blackmail motivation

Correct Answers: B, C

Correct Answers

 

 

Answer B is correct because Insider threat means a person with legitimate internal access who causes harm intentionally or accidentally. It belongs in the fixed-count answer set because it covers one of the stated requirements. Blackmail motivation instead serves a goal of coercing a victim by threatening disclosure, damage, or other harmful action and cannot replace this function.

Answer C is correct because Ideological motivation means a goal driven by philosophical, political, or social beliefs. It belongs in the fixed-count answer set because it covers one of the stated requirements. Organized crime instead serves a financially motivated criminal group that operates in a coordinated and often professional manner and cannot replace this function.

Incorrect Answers

 

Answer A is incorrect because Organized crime means a financially motivated criminal group that operates in a coordinated and often professional manner. The scenario calls for Insider threat, Ideological motivation. Selecting this option would leave one of those required functions uncovered.

Answer D is incorrect because Financial gain motivation means a goal of directly or indirectly obtaining money. The scenario calls for Insider threat, Ideological motivation. Selecting this option would leave one of those required functions uncovered. For example, Ideological motivation is required for a goal driven by philosophical, political, or social beliefs.

Answer E is incorrect because Blackmail motivation means a goal of coercing a victim by threatening disclosure, damage, or other harmful action. The required choices are Insider threat, Ideological motivation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 4

To monetize fraud, ransomware, extortion, or stolen information, which security approach should be selected?

  1. Organized crime
  2. Financial gain motivation
  3. Ideological motivation
  4. Nation-state threat actor

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Organized crime means a financially motivated criminal group that operates in a coordinated and often professional manner. The requirement maps directly to this function, whereas Financial gain motivation is aimed at a goal of directly or indirectly obtaining money.

Incorrect Answers

 

Answer B is incorrect because Financial gain motivation refers to a goal of directly or indirectly obtaining money. That concept can be valid in another scenario, but this question is testing a financially motivated criminal group that operates in a coordinated and often professional manner; Organized crime therefore fits the requirement more directly.

Answer C is incorrect because Ideological motivation refers to a goal driven by philosophical, political, or social beliefs. This could be appropriate elsewhere, but the required function is a financially motivated criminal group that operates in a coordinated and often professional manner; that makes Organized crime the precise choice.

Answer D is incorrect because Nation-state threat actor refers to a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives. That concept can be valid in another scenario, but this question is testing a financially motivated criminal group that operates in a coordinated and often professional manner; Organized crime therefore fits the requirement more directly.

 

Question 5

To interrupt business operations rather than primarily stealing information, which security approach should be selected?

  1. Nation-state threat actor
  2. Service disruption motivation
  3. Espionage motivation
  4. Financial gain motivation

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Service disruption motivation means a goal of making systems or services unavailable or unreliable. That makes it the best answer here; Financial gain motivation addresses a goal of directly or indirectly obtaining money, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Nation-state threat actor refers to a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives. The key mismatch is functional: Service disruption motivation addresses a goal of making systems or services unavailable or unreliable, the need stated by the question.

Answer C is incorrect because Espionage motivation refers to a goal centered on covertly obtaining sensitive government, military, business, or research information. The scenario instead requires a goal of making systems or services unavailable or unreliable, which is why Service disruption motivation is the better answer; this option serves the different function defined above.

Answer D is incorrect because Financial gain motivation refers to a goal of directly or indirectly obtaining money. The question is not asking for this function. It is testing a goal of making systems or services unavailable or unreliable, so Service disruption motivation is the stronger fit.

 

Question 6

Which government-sponsored or government-aligned adversary often has significant resources, patience, and strategic objectives?

  1. Espionage motivation
  2. War motivation
  3. Service disruption motivation
  4. Nation-state threat actor

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Nation-state threat actor means a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives. The requirement maps directly to this function, whereas Service disruption motivation is aimed at a goal of making systems or services unavailable or unreliable.

Incorrect Answers

 

Answer A is incorrect because Espionage motivation refers to a goal centered on covertly obtaining sensitive government, military, business, or research information. The question is not asking for this function. It is testing a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives, so Nation-state threat actor is the stronger fit.

Answer B is incorrect because War motivation refers to a goal connected to military or geopolitical conflict. The key mismatch is functional: Nation-state threat actor addresses a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives, the need stated by the question.

Answer C is incorrect because Service disruption motivation refers to a goal of making systems or services unavailable or unreliable. That concept can be valid in another scenario, but this question is testing a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives; Nation-state threat actor therefore fits the requirement more directly.

 

Question 7

A review during a threat-intelligence assessment identifies two gaps. One requires government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives. The other requires technology deployed or used without formal approval or governance from the responsible IT or security organization. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Organized crime
  2. Data exfiltration motivation
  3. Insider threat
  4. Shadow IT
  5. Nation-state threat actor

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because Shadow IT means technology deployed or used without formal approval or governance from the responsible IT or security organization. The fixed-count item needs this function in the answer set. Insider threat covers a person with legitimate internal access who causes harm intentionally or accidentally, a different requirement.

Answer E is correct because Nation-state threat actor means a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives. This option satisfies a specific requirement in the stem; Organized crime serves a financially motivated criminal group that operates in a coordinated and often professional manner and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Organized crime means a financially motivated criminal group that operates in a coordinated and often professional manner. Every answer slot must map to a stated requirement. The correct set is Shadow IT, Nation-state threat actor, so this option cannot replace one of those selections.

Answer B is incorrect because Data exfiltration motivation means a goal centered on stealing information from the target environment. The fixed-count answer set is Shadow IT, Nation-state threat actor; this option does not fill one of those named functions.

Answer C is incorrect because Insider threat means a person with legitimate internal access who causes harm intentionally or accidentally. The fixed-count answer set is Shadow IT, Nation-state threat actor; this option does not fill one of those named functions.

 

Question 8

To force payment or behavior through leverage over the victim, which security approach should be selected?

  1. Unskilled attacker
  2. Blackmail motivation
  3. Ideological motivation
  4. Service disruption motivation

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Blackmail motivation means a goal of coercing a victim by threatening disclosure, damage, or other harmful action. The deciding point is functional fit: this option covers the stated need, while Service disruption motivation addresses a goal of making systems or services unavailable or unreliable.

Incorrect Answers

 

Answer A is incorrect because Unskilled attacker refers to an attacker with limited original capability who often relies on publicly available tools, scripts, or instructions. The scenario instead requires a goal of coercing a victim by threatening disclosure, damage, or other harmful action, which is why Blackmail motivation is the better answer; this option serves the different function defined above.

Answer C is incorrect because Ideological motivation refers to a goal driven by philosophical, political, or social beliefs. That concept can be valid in another scenario, but this question is testing a goal of coercing a victim by threatening disclosure, damage, or other harmful action; Blackmail motivation therefore fits the requirement more directly.

Answer D is incorrect because Service disruption motivation refers to a goal of making systems or services unavailable or unreliable. The scenario instead requires a goal of coercing a victim by threatening disclosure, damage, or other harmful action, which is why Blackmail motivation is the better answer; this option serves the different function defined above.

 

Question 9

A review during a threat-intelligence assessment identifies two gaps. One requires attacker with limited original capability who often relies on publicly available tools, scripts, or instructions. The other requires financially motivated criminal group that operates in a coordinated and often professional manner. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Hacktivist
  2. Organized crime
  3. Shadow IT
  4. Service disruption motivation
  5. Unskilled attacker

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because Organized crime means a financially motivated criminal group that operates in a coordinated and often professional manner. This option satisfies a specific requirement in the stem; Service disruption motivation serves a goal of making systems or services unavailable or unreliable and therefore is not interchangeable with it.

Answer E is correct because Unskilled attacker means an attacker with limited original capability who often relies on publicly available tools, scripts, or instructions. This option satisfies a specific requirement in the stem; Shadow IT serves technology deployed or used without formal approval or governance from the responsible IT or security organization and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Hacktivist means an attacker motivated primarily by political, social, or ideological goals. The question requires exactly 2 selections: Unskilled attacker, Organized crime. This option falls outside that required set. For example, Organized crime is required for a financially motivated criminal group that operates in a coordinated and often professional manner.

Answer C is incorrect because Shadow IT means technology deployed or used without formal approval or governance from the responsible IT or security organization. The required choices are Unskilled attacker, Organized crime. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Service disruption motivation means a goal of making systems or services unavailable or unreliable. The question requires exactly 2 selections: Unskilled attacker, Organized crime. This option falls outside that required set. For example, Organized crime is required for a financially motivated criminal group that operates in a coordinated and often professional manner.

 

Question 10

What is a goal of retaliating against an individual or organization for a perceived grievance?

  1. Unskilled attacker
  2. Insider threat
  3. Revenge motivation
  4. Blackmail motivation

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Revenge motivation means a goal of retaliating against an individual or organization for a perceived grievance. The requirement maps directly to this function, whereas Insider threat is aimed at a person with legitimate internal access who causes harm intentionally or accidentally.

Incorrect Answers

 

Answer A is incorrect because Unskilled attacker refers to an attacker with limited original capability who often relies on publicly available tools, scripts, or instructions. The question is not asking for this function. It is testing a goal of retaliating against an individual or organization for a perceived grievance, so Revenge motivation is the stronger fit.

Answer B is incorrect because Insider threat refers to a person with legitimate internal access who causes harm intentionally or accidentally. This could be appropriate elsewhere, but the required function is a goal of retaliating against an individual or organization for a perceived grievance; that makes Revenge motivation the precise choice.

Answer D is incorrect because Blackmail motivation refers to a goal of coercing a victim by threatening disclosure, damage, or other harmful action. This could be appropriate elsewhere, but the required function is a goal of retaliating against an individual or organization for a perceived grievance; that makes Revenge motivation the precise choice.

 

Question 11

Reviewers working through a threat-intelligence assessment identify three separate needs: financially motivated criminal group that operates in a coordinated and often professional manner; goal centered on stealing information from the target environment; goal of making systems or services unavailable or unreliable. Which THREE choices map to those needs? Choose THREE.

  1. Data exfiltration motivation
  2. Hacktivist
  3. Shadow IT
  4. Nation-state threat actor
  5. Service disruption motivation
  6. Organized crime

Correct Answers: A, E, F

Correct Answers

 

 

Answer A is correct because Data exfiltration motivation means a goal centered on stealing information from the target environment. This option satisfies a specific requirement in the stem; Shadow IT serves technology deployed or used without formal approval or governance from the responsible IT or security organization and therefore is not interchangeable with it.

Answer E is correct because Service disruption motivation means a goal of making systems or services unavailable or unreliable. This selection maps directly to one of the named needs. Nation-state threat actor addresses a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives, so it does not satisfy the same slot.

Answer F is correct because Organized crime means a financially motivated criminal group that operates in a coordinated and often professional manner. One required function is exactly what this option provides. Shadow IT may be useful elsewhere, but it is used for technology deployed or used without formal approval or governance from the responsible IT or security organization.

Incorrect Answers

 

Answer B is incorrect because Hacktivist means an attacker motivated primarily by political, social, or ideological goals. The required choices are Organized crime, Data exfiltration motivation, Service disruption motivation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer C is incorrect because Shadow IT means technology deployed or used without formal approval or governance from the responsible IT or security organization. The fixed-count answer set is Organized crime, Data exfiltration motivation, Service disruption motivation; this option does not fill one of those named functions.

Answer D is incorrect because Nation-state threat actor means a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives. The required choices are Organized crime, Data exfiltration motivation, Service disruption motivation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 12

Which term describes technology deployed or used without formal approval or governance from the responsible IT or security organization?

  1. Shadow IT
  2. Ideological motivation
  3. War motivation
  4. Unskilled attacker

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Shadow IT means technology deployed or used without formal approval or governance from the responsible IT or security organization. That makes it the best answer here; Unskilled attacker addresses an attacker with limited original capability who often relies on publicly available tools, scripts, or instructions, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because Ideological motivation refers to a goal driven by philosophical, political, or social beliefs. The question is not asking for this function. It is testing technology deployed or used without formal approval or governance from the responsible IT or security organization, so Shadow IT is the stronger fit.

Answer C is incorrect because War motivation refers to a goal connected to military or geopolitical conflict. This could be appropriate elsewhere, but the required function is technology deployed or used without formal approval or governance from the responsible IT or security organization; that makes Shadow IT the precise choice.

Answer D is incorrect because Unskilled attacker refers to an attacker with limited original capability who often relies on publicly available tools, scripts, or instructions. The key mismatch is functional: Shadow IT addresses technology deployed or used without formal approval or governance from the responsible IT or security organization, the need stated by the question.

 

Question 13

Two requirements remain open in a threat-intelligence assessment: attacker motivated primarily by political, social, or ideological goals; goal connected to military or geopolitical conflict. Which TWO options close those specific gaps? Choose TWO.

  1. Unskilled attacker
  2. Espionage motivation
  3. War motivation
  4. Financial gain motivation
  5. Hacktivist

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because War motivation means a goal connected to military or geopolitical conflict. The fixed-count item needs this function in the answer set. Unskilled attacker covers an attacker with limited original capability who often relies on publicly available tools, scripts, or instructions, a different requirement.

Answer E is correct because Hacktivist means an attacker motivated primarily by political, social, or ideological goals. One required function is exactly what this option provides. Espionage motivation may be useful elsewhere, but it is used for a goal centered on covertly obtaining sensitive government, military, business, or research information.

Incorrect Answers

 

Answer A is incorrect because Unskilled attacker means an attacker with limited original capability who often relies on publicly available tools, scripts, or instructions. The required choices are Hacktivist, War motivation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer B is incorrect because Espionage motivation means a goal centered on covertly obtaining sensitive government, military, business, or research information. Every answer slot must map to a stated requirement. The correct set is Hacktivist, War motivation, so this option cannot replace one of those selections.

Answer D is incorrect because Financial gain motivation means a goal of directly or indirectly obtaining money. The question requires exactly 2 selections: Hacktivist, War motivation. This option falls outside that required set. For example, Hacktivist is required for an attacker motivated primarily by political, social, or ideological goals.

 

Question 14

Two requirements remain open in a threat-intelligence assessment: person with legitimate internal access who causes harm intentionally or accidentally; goal of retaliating against an individual or organization for a perceived grievance. Which TWO options close those specific gaps? Choose TWO.

  1. Data exfiltration motivation
  2. Insider threat
  3. Shadow IT
  4. Revenge motivation
  5. Nation-state threat actor

Correct Answers: B, D

Correct Answers

 

 

Answer B is correct because Insider threat means a person with legitimate internal access who causes harm intentionally or accidentally. This option satisfies a specific requirement in the stem; Nation-state threat actor serves a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives and therefore is not interchangeable with it.

Answer D is correct because Revenge motivation means a goal of retaliating against an individual or organization for a perceived grievance. This option satisfies a specific requirement in the stem; Data exfiltration motivation serves a goal centered on stealing information from the target environment and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Data exfiltration motivation means a goal centered on stealing information from the target environment. The required choices are Insider threat, Revenge motivation. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer C is incorrect because Shadow IT means technology deployed or used without formal approval or governance from the responsible IT or security organization. Every answer slot must map to a stated requirement. The correct set is Insider threat, Revenge motivation, so this option cannot replace one of those selections.

Answer E is incorrect because Nation-state threat actor means a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives. The question requires exactly 2 selections: Insider threat, Revenge motivation. This option falls outside that required set.

 

Question 15

What is a person with legitimate internal access who causes harm intentionally or accidentally?

  1. Insider threat
  2. War motivation
  3. Ideological motivation
  4. Unskilled attacker

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Insider threat means a person with legitimate internal access who causes harm intentionally or accidentally. The requirement maps directly to this function, whereas War motivation is aimed at a goal connected to military or geopolitical conflict.

Incorrect Answers

 

Answer B is incorrect because War motivation refers to a goal connected to military or geopolitical conflict. This could be appropriate elsewhere, but the required function is a person with legitimate internal access who causes harm intentionally or accidentally; that makes Insider threat the precise choice.

Answer C is incorrect because Ideological motivation refers to a goal driven by philosophical, political, or social beliefs. The scenario instead requires a person with legitimate internal access who causes harm intentionally or accidentally, which is why Insider threat is the better answer; this option serves the different function defined above.

Answer D is incorrect because Unskilled attacker refers to an attacker with limited original capability who often relies on publicly available tools, scripts, or instructions. The key mismatch is functional: Insider threat addresses a person with legitimate internal access who causes harm intentionally or accidentally, the need stated by the question.

 

Question 16

Which financially motivated criminal group operates in a coordinated and often professional manner?

  1. Data exfiltration motivation
  2. Organized crime
  3. Blackmail motivation
  4. Unskilled attacker

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Organized crime means a financially motivated criminal group that operates in a coordinated and often professional manner. That makes it the best answer here; Blackmail motivation addresses a goal of coercing a victim by threatening disclosure, damage, or other harmful action, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Data exfiltration motivation refers to a goal centered on stealing information from the target environment. The key mismatch is functional: Organized crime addresses a financially motivated criminal group that operates in a coordinated and often professional manner, the need stated by the question.

Answer C is incorrect because Blackmail motivation refers to a goal of coercing a victim by threatening disclosure, damage, or other harmful action. This could be appropriate elsewhere, but the required function is a financially motivated criminal group that operates in a coordinated and often professional manner; that makes Organized crime the precise choice.

Answer D is incorrect because Unskilled attacker refers to an attacker with limited original capability who often relies on publicly available tools, scripts, or instructions. The scenario instead requires a financially motivated criminal group that operates in a coordinated and often professional manner, which is why Organized crime is the better answer; this option serves the different function defined above.

 

Question 17

To use disruption, defacement, leaks, or publicity to advance a cause, which security approach should be selected?

  1. Unskilled attacker
  2. Insider threat
  3. Hacktivist
  4. Blackmail motivation

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Hacktivist means an attacker motivated primarily by political, social, or ideological goals. That is the function the question is testing. Unskilled attacker would instead be used for an attacker with limited original capability who often relies on publicly available tools, scripts, or instructions.

Incorrect Answers

 

Answer A is incorrect because Unskilled attacker refers to an attacker with limited original capability who often relies on publicly available tools, scripts, or instructions. This could be appropriate elsewhere, but the required function is an attacker motivated primarily by political, social, or ideological goals; that makes Hacktivist the precise choice.

Answer B is incorrect because Insider threat refers to a person with legitimate internal access who causes harm intentionally or accidentally. The question is not asking for this function. It is testing an attacker motivated primarily by political, social, or ideological goals, so Hacktivist is the stronger fit.

Answer D is incorrect because Blackmail motivation refers to a goal of coercing a victim by threatening disclosure, damage, or other harmful action. The scenario instead requires an attacker motivated primarily by political, social, or ideological goals, which is why Hacktivist is the better answer; this option serves the different function defined above.

 

Question 18

To introduce unmanaged applications, services, or devices that bypass normal controls, which security approach should be selected?

  1. Blackmail motivation
  2. Unskilled attacker
  3. Financial gain motivation
  4. Shadow IT

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Shadow IT means technology deployed or used without formal approval or governance from the responsible IT or security organization. This is the precise fit for the scenario. Financial gain motivation serves the different purpose of a goal of directly or indirectly obtaining money.

Incorrect Answers

 

Answer A is incorrect because Blackmail motivation refers to a goal of coercing a victim by threatening disclosure, damage, or other harmful action. That concept can be valid in another scenario, but this question is testing technology deployed or used without formal approval or governance from the responsible IT or security organization; Shadow IT therefore fits the requirement more directly.

Answer B is incorrect because Unskilled attacker refers to an attacker with limited original capability who often relies on publicly available tools, scripts, or instructions. That concept can be valid in another scenario, but this question is testing technology deployed or used without formal approval or governance from the responsible IT or security organization; Shadow IT therefore fits the requirement more directly.

Answer C is incorrect because Financial gain motivation refers to a goal of directly or indirectly obtaining money. The concept is valid, but it does not match this stem. The required function is technology deployed or used without formal approval or governance from the responsible IT or security organization, which maps to Shadow IT.

 

Question 19

What is a goal of coercing a victim by threatening disclosure, damage, or other harmful action?

  1. Organized crime
  2. Revenge motivation
  3. Blackmail motivation
  4. Service disruption motivation

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Blackmail motivation means a goal of coercing a victim by threatening disclosure, damage, or other harmful action. That makes it the best answer here; Service disruption motivation addresses a goal of making systems or services unavailable or unreliable, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Organized crime refers to a financially motivated criminal group that operates in a coordinated and often professional manner. The question is not asking for this function. It is testing a goal of coercing a victim by threatening disclosure, damage, or other harmful action, so Blackmail motivation is the stronger fit.

Answer B is incorrect because Revenge motivation refers to a goal of retaliating against an individual or organization for a perceived grievance. This could be appropriate elsewhere, but the required function is a goal of coercing a victim by threatening disclosure, damage, or other harmful action; that makes Blackmail motivation the precise choice.

Answer D is incorrect because Service disruption motivation refers to a goal of making systems or services unavailable or unreliable. This could be appropriate elsewhere, but the required function is a goal of coercing a victim by threatening disclosure, damage, or other harmful action; that makes Blackmail motivation the precise choice.

 

Question 20

To conduct espionage, disruption, or strategic campaigns with substantial capability, which security approach should be selected?

  1. Data exfiltration motivation
  2. Hacktivist
  3. Espionage motivation
  4. Nation-state threat actor

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Nation-state threat actor means a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives. The requirement maps directly to this function, whereas Data exfiltration motivation is aimed at a goal centered on stealing information from the target environment.

Incorrect Answers

 

Answer A is incorrect because Data exfiltration motivation refers to a goal centered on stealing information from the target environment. The concept is valid, but it does not match this stem. The required function is a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives, which maps to Nation-state threat actor.

Answer B is incorrect because Hacktivist refers to an attacker motivated primarily by political, social, or ideological goals. The key mismatch is functional: Nation-state threat actor addresses a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives, the need stated by the question.

Answer C is incorrect because Espionage motivation refers to a goal centered on covertly obtaining sensitive government, military, business, or research information. The question is not asking for this function. It is testing a government-sponsored or government-aligned adversary that often has significant resources, patience, and strategic objectives, so Nation-state threat actor is the stronger fit. This question specifically tests the requirement represented by Nation-state threat actor.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!