Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsHard

A security operations center (SOC) analyst is investigating a series of alerts indicating unusual login attempts from foreign IP addresses for several high-privilege accounts. The alerts show successful logins followed by rapid data transfers to external servers. The analyst needs to categorize this activity as a specific type of threat. Which threat category best describes this situation?

  1. APhishing
  2. BInsider Threat
  3. CDistributed Denial of Service (DDoS)
  4. DAdvanced Persistent Threat (APT)
Show answer & explanation

Correct answer: D. Advanced Persistent Threat (APT)

Unusual login attempts from foreign IPs, targeting high-privilege accounts, successful logins, and rapid data exfiltration are hallmarks of sophisticated, long-term targeted attacks characteristic of an Advanced Persistent Threat (APT).

Why the other options are wrong

  • A. Phishing is a delivery mechanism for initial access, not the entire sophisticated attack described.
  • B. Insider threats originate from within the organization, not typically foreign IPs.
  • C. DDoS attacks aim to make a service unavailable, not to gain access and exfiltrate data.

Advanced Persistent Threat (APT)

A stealthy and continuous computer hacking process, often orchestrated by nation-states or highly organized groups, targeting organizations for a specific objective, typically data exfiltration.

  • Highly skilled and well-funded attackers.
  • Long-term, targeted campaigns.
  • Focus on stealth and data exfiltration.
  • Often uses multiple attack vectors.

Memory trick: APT is Advanced, Persistent, and Targeted.

More Cybersecurity Fundamentals questions