FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A bank classifies threat actors by motivation. Which pairing of actor and typical primary motivation is most accurate?
Organised cybercriminal groups are mainly motivated by financial gain, using ransomware, fraud and data theft. Hacktivists seek ideological publicity and nation-states pursue strategic goals such as espionage, so the other pairings misattribute motives.
- AOrganised cybercriminal group: financial gainCorrect
- BHacktivist: long-term state intelligence collection
- CNation-state actor: publicity for a social cause only
- DDisgruntled insider: espionage on behalf of a foreign ministry as the defining motive
Explanation
Organised criminals typically seek profit through ransomware, fraud and theft. Hacktivists pursue ideological or publicity goals, and nation-states pursue strategic objectives such as espionage or disruption. The insider option misstates the usual grievance-driven motive.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A bank estimates that a phishing-led breach has an annual probability of 8% and a loss of USD 25 million if it occurs. A proposed control pa…
- A bank's board wants key risk indicators (KRIs) to give early warning of deteriorating cyber control health. Which of the following is the b…
- A bank's payment-processing database is hit by ransomware that encrypts the files, so tellers and customers cannot access account balances f…
- Following a ransomware event, a firm finds that its backups were stored on the same network and were encrypted along with production data. W…
- When a bank quantifies cyber risk using scenario analysis, which practice best improves the reliability of the resulting estimates?
- A bank's risk team ranks a customer-data repository as high priority because a breach would expose personal information and trigger regulato…