Cisco CCNP Security Core (SCOR) 350-701Network SecurityHard
A security operations center (SOC) analyst is investigating a series of sophisticated, stealthy attacks targeting critical intellectual property. These attacks involve custom malware that evades traditional signature-based detection and exhibit highly targeted reconnaissance and data exfiltration techniques over extended periods. The attackers leverage legitimate system tools and processes to blend in with normal network activity. Which type of threat best describes this scenario?
- APhishing Campaign
- BDistributed Denial of Service (DDoS)
- CRansomware Attack
- DAdvanced Persistent Threat (APT)
Show answer & explanationAnswer & explanation
Correct answer: D. Advanced Persistent Threat (APT)
The description of sophisticated, stealthy, highly targeted attacks using custom malware to evade detection, involving reconnaissance and data exfiltration over extended periods, and leveraging legitimate tools to blend in, precisely matches the characteristics of an Advanced Persistent Threat (APT). APTs are typically well-funded groups (often nation-states) aiming for long-term access to sensitive information.
Why the other options are wrong
- A. Phishing campaigns are a delivery mechanism, not the overarching threat type describing the post-compromise activities.
- B. DDoS attacks focus on disrupting service availability, not stealthy data exfiltration and long-term persistence.
- C. Ransomware attacks encrypt data for financial gain and typically announce their presence, which is contrary to the stealthy, persistent nature described.
Advanced Persistent Threat (APT)
A stealthy and continuous computer hacking process, often orchestrated by a nation-state, targeting a specific entity for business or political motives.
- Highly targeted and sophisticated
- Focus on long-term access and data exfiltration
- Evades traditional security measures
- Uses custom malware and legitimate tools
Memory trick: APT: Advanced, Persistent, Stealthy.