FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A bank's risk committee is classifying threat actors. One group aims to disrupt a bank's public website during a political controversy to publicise its cause, with no intent to steal funds. Which classification and primary motivation is most appropriate?
The group is best classed as hacktivist. Its aim is ideological or publicity-driven disruption linked to a political controversy rather than theft. Cybercriminals pursue profit, state actors usually act covertly for strategic or intelligence goals, and nothing in the scenario points to an insider with a grievance.
- AHacktivist, motivated by ideology or publicityCorrect
- BOrganised cybercriminal group, motivated by direct financial gain
- CState-sponsored actor, motivated by long-term espionage
- DMalicious insider, motivated by personal grievance with the employer
Explanation
Disruption timed to a political issue, aimed at publicity and without theft, is characteristic of hacktivism. Cybercriminals seek profit, state actors typically seek intelligence or strategic effect covertly, and the scenario describes no insider.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- After a penetration test reveals that privileged accounts at a bank are shared among administrators with no individual accountability, which…
- A bank allocates its cyber risk governance responsibilities under a three lines model. Which arrangement is most consistent with that model?
- A mid-sized bank's security team observes a well-funded group that maintains undetected access to its payment-messaging network for many mon…
- A bank has three cyber risk treatment options for a scenario with inherent expected annual loss of USD 3.0 million. Option A: a control cost…
- In a case review, a firm's intrusion detection system generated alerts on unusual outbound data transfers for several weeks, but no analyst …
- A regional bank's chief information security officer (CISO) reports to the chief risk officer and the board risk committee that the security…