5. Which of the following threat vectors is most commonly utilized by insider threat actors attempting data exfiltration?

Answer: A

Explanation:

Unidentified removable devices are the most commonly utilized threat vector by insider threat actors attempting data exfiltration.

Insider threat actors frequently exploit unidentified removable devices to transfer sensitive data outside the organization, as these devices can easily bypass security measures if not properly monitored.

A) Unidentified removable devices

This option is correct because insider threat actors often use removable devices, such as USB drives, to exfiltrate data discreetly. These devices are portable and can be connected to various systems without raising immediate suspicion, making them an effective tool for data theft.

B) Default network device credentials

While using default network device credentials can pose a security risk, it is more commonly associated with external threat actors looking to gain unauthorized access. Insider threats typically have legitimate access and prefer methods that do not require exploiting default credentials for data exfiltration.

C) Spear-phishing emails

Spear-phishing emails are primarily used by external attackers to gain access to systems or sensitive information. Although insiders may utilize phishing techniques in certain contexts, they are less likely to rely on this method for exfiltrating data since they already possess access.

D) Impersonation of business units through typosquatting

This method involves creating deceptive websites or communications to mislead users, which is more relevant to external phishing attacks. Insider threats usually leverage their access and knowledge of the organization to use more direct methods, such as removable devices.

Conclusion

Unidentified removable devices are the primary vector for insider threat actors because they provide a straightforward and inconspicuous means for data exfiltration. Other options, such as default credentials, spear-phishing, and impersonation, either pertain more to external threats or are less effective for insiders who already have legitimate access to sensitive information.