CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

A payroll administrator has legitimate access to the HR system to process employee salaries. Investigators discover the administrator quietly modified their own salary figures over several months, using their normal login credentials and avoiding any detection triggers. Which type of threat actor does this best describe?

  1. AScript kiddie
  2. BAdvanced persistent threat
  3. CMalicious insider
  4. DHacktivist
Show answer & explanation

Correct answer: C. Malicious insider

A malicious insider is an authorized user who abuses legitimate access for personal gain, which matches the administrator using valid credentials to alter their own pay. This differs from external actors like script kiddies or APTs who must first breach a perimeter, and from hacktivists who act for ideological reasons.

Why the other options are wrong

  • A. Wrong: script kiddies use pre-made external exploits, not legitimate insider access.
  • B. Wrong: APTs are typically external, well-funded, long-term espionage campaigns.
  • D. Wrong: no political or social motivation is present.

Malicious Insider

An employee, contractor, or partner who intentionally misuses authorized access to harm the organization or benefit themselves.

  • Already has legitimate credentials, bypassing perimeter defenses
  • Motivated by financial gain, revenge, or ideology
  • Detected mainly through behavior analytics and audit logging

Memory trick: The insider already has the keys—no need to pick the lock.

More Threats, Vulnerabilities, and Mitigations questions