Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsHard
A security operations center (SOC) analyst is investigating a series of alerts indicating unusual login attempts from foreign IP addresses for several high-privilege accounts. The alerts show successful logins followed by rapid data transfers to external servers. The analyst needs to categorize this activity as a specific type of threat. Which threat category best describes this situation?
- APhishing
- BInsider Threat
- CDistributed Denial of Service (DDoS)
- DAdvanced Persistent Threat (APT)
Show answer & explanationAnswer & explanation
Correct answer: D. Advanced Persistent Threat (APT)
Unusual login attempts from foreign IPs, targeting high-privilege accounts, successful logins, and rapid data exfiltration are hallmarks of sophisticated, long-term targeted attacks characteristic of an Advanced Persistent Threat (APT).
Why the other options are wrong
- A. Phishing is a delivery mechanism for initial access, not the entire sophisticated attack described.
- B. Insider threats originate from within the organization, not typically foreign IPs.
- C. DDoS attacks aim to make a service unavailable, not to gain access and exfiltrate data.
Advanced Persistent Threat (APT)
A stealthy and continuous computer hacking process, often orchestrated by nation-states or highly organized groups, targeting organizations for a specific objective, typically data exfiltration.
- Highly skilled and well-funded attackers.
- Long-term, targeted campaigns.
- Focus on stealth and data exfiltration.
- Often uses multiple attack vectors.
Memory trick: APT is Advanced, Persistent, and Targeted.