FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A bank classifies four threat scenarios by actor motivation to prioritize controls. Which pairing of actor and primary motivation is most accurate?
Organized cybercriminal groups are primarily motivated by financial gain, using ransomware, fraud and data theft. The other pairings are mismatched: nation-states pursue espionage or strategic aims, hacktivists seek publicity for causes, and grievance insiders typically seek revenge or sabotage rather than website defacement for ideology.
- ANation-state actor: mainly quick personal financial gain through small card fraud
- BHacktivist: mainly strategic espionage over many years with no public disclosure
- COrganized cybercriminal group: mainly financial gain through ransomware and fraudCorrect
- DInsider with a grievance: mainly ideological protest by defacing public websites
Explanation
Organized criminal groups are primarily financially motivated, using ransomware, fraud and data theft for profit. Nation-states are chiefly associated with espionage or strategic disruption, not small card fraud. Hacktivists seek public attention for causes, not covert espionage, and grievance insiders typically seek revenge or sabotage.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A bank's payment-processing database is hit by ransomware that encrypts the files, so tellers and customers cannot access account balances f…
- Following a ransomware event, a firm finds that its backups were stored on the same network and were encrypted along with production data. W…
- When a bank quantifies cyber risk using scenario analysis, which practice best improves the reliability of the resulting estimates?
- A bank's risk team ranks a customer-data repository as high priority because a breach would expose personal information and trigger regulato…
- After a major breach, a post-incident review finds that security alerts had fired for weeks but were not escalated because the monitoring te…
- After an incident, a bank's investigation finds that a former employee's account was never deactivated and was used to download client files…