200-201 Security Concepts Practice Question
A financial services firm is building a threat model and wants to classify an attacker who is highly skilled, well funded, and focused on stealing intellectual property from a specific set of companies over a long period. Which threat actor category best fits this profile?
⚠ Common exam trap
The trap here is focusing on the theft of intellectual property alone, which any actor might attempt, instead of weighing the funding, skill, and long-term persistence that define an advanced persistent threat.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Advanced persistent threat
An advanced persistent threat is characterized by significant resources, advanced skills, and sustained, stealthy operations against specific targets, often for espionage or intellectual property theft. The scenario's emphasis on long duration, funding, and a defined victim set aligns with APT behavior. Hacktivists are ideologically driven, script kiddies lack sophistication and resources, and insider threats are authorized users, so none matches the described external, well-funded, persistent actor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Script kiddie
Why it's wrong here
Script kiddies are low-skill actors who use existing tools and exploits without deep understanding, often for curiosity or notoriety. They lack the funding, patience, and targeting discipline described in the scenario. Their activity tends to be noisy and opportunistic rather than a sustained campaign against selected companies for intellectual property, so this category does not fit the profile.
- ✗
Hacktivist
Why it's wrong here
Hacktivists are motivated by ideology or social causes and typically pursue defacement, denial of service, or data leaks to publicize a message. They rarely sustain long-term, well-funded campaigns aimed at stealing intellectual property for competitive or strategic gain. The described profile emphasizes patience, resources, and targeted theft, which does not align with hacktivist objectives or methods.
- ✗
Insider threat
Why it's wrong here
An insider threat is a person with authorized access, such as an employee or contractor, who abuses that access. While insiders can steal intellectual property, the profile describes an external actor with substantial resources conducting long-term campaigns against multiple companies. The funding, skill, and multi-victim targeting point to an external advanced actor rather than a trusted internal user.
- ✓
Advanced persistent threat
Why this is correct
An advanced persistent threat is a well-resourced actor, often state-sponsored, that conducts prolonged campaigns against specific targets. The combination of high skill, significant funding, focus on a defined set of victims, and long-term intellectual property theft matches the APT profile exactly. APTs prioritize stealth and persistence over quick disruption, which is consistent with the described behavior.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.