exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 181 discussion

Actual exam question from CompTIA's CAS-004
Question #: 181
Topic #: 1
[All CAS-004 Questions]

A company security engineer arrives at work to face the following scenario:
1. Website defacement
2. Calls from the company president indicating the website needs to be fixed immediately because it is damaging the brand
3. A job offer from the company's competitor
4. A security analyst's investigative report, based on logs from the past six months, describing how lateral movement across the network from various IP addresses originating from a foreign adversary country resulted in exfiltrated data
Which of the following threat actors is MOST likely involved?

  • A. Organized crime
  • B. Script kiddie
  • C. APT/nation-state
  • D. Competitor
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mr_BuCk3th34D
Highly Voted 1 year, 4 months ago
Selected Answer: C
Competitor is not an "threat actor". Based on the information provided, it seems that the most likely threat actor involved is an APT/nation-state. This is based on the fact that the security analyst's investigative report describes lateral movement across the network from various IP addresses originating from a foreign adversary country, which typically indicates a more advanced and sophisticated type of threat actor. A competitor is also a possibility, but given the other indicators (website defacement, calls from the company president about the damage to the brand) and the fact that the security analyst's report specifically mentions a foreign adversary country, it seems more likely that an APT/nation-state is the primary threat actor in this scenario.
upvoted 6 times
...
deeden
Most Recent 5 months ago
Selected Answer: C
Well, it is possible that the Competitor might have hired APT to do the dirty work LOL but nevertheless evidence points to an advanced ATT&CK
upvoted 1 times
...
ThatGuyOverThere
6 months, 2 weeks ago
Given 2-3 of the items listed point to competitor more than APT/nation-state, I'm going with D. The only indicator of APT/nation-state is foreign addresses but competitors cross nations, including foreign adversary countries. You can also have a competitor pay a threat actor to work on their behalf or simply use VPNs/proxies to make an attack appear like it's from a different country. Whether or not competitors are a "main" threat actor type I think is irrelevant. It is absolutely a threat actor type and the bulk of the indicators point to it.
upvoted 1 times
...
jt2oux
8 months ago
I'm choosing C. A competitor job offer is easily explained by the website defacement that is damaging the brand. Competitors often keep close watch of each competing entity website as a part of normal business. They would possibly be the first to discover the website defacement in the first place.
upvoted 1 times
...
last_resort
1 year, 1 month ago
Selected Answer: C
Going with C. Nation state/APTs are known for false flag attacks
upvoted 2 times
...
FOURDUE
1 year, 2 months ago
Selected Answer: C
4. A security analyst's investigative report, based on logs from the past six months, describing how lateral movement across the network from various IP addresses originating from a foreign adversary country resulted in exfiltrated data
upvoted 2 times
...
AnnoyingIAGuy
1 year, 3 months ago
I would say competitor. APT/nation states don't necessarily benefit from defacement of a companies "brand". The email for a job opening could be a distractor, but I take it as relevant. The data exfiltration could also be a good indicator of a competitor. The foreign IPs are very easily explained away with the use of VPNs.
upvoted 1 times
...
hidady
1 year, 4 months ago
D is the correct answer
upvoted 1 times
...
chil7chil7
1 year, 5 months ago
Selected Answer: D
I would say competitor the whole process is trying to make the brand reputation goes down.
upvoted 2 times
chil7chil7
1 year, 5 months ago
sorry it's C, competitor is not main threat actor... and it's also more like insider to sell IP to competitor
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago