Question 833 of 1,013
SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question
A security analyst discovers that an attacker maintained persistent access to a corporate network for six months, moving laterally between systems and exfiltrating sensitive data. The attacker used custom malware that evaded antivirus and established multiple backdoors. Which of the following best describes this type of threat actor and their campaign?
⚠ Common exam trap
A common mix-up: candidates confuse 'advanced persistent threat' with a specific exploit technique like a zero-day, or assume any long-term access is an insider threat, but the key differentiator is the external, resource-intensive, and stealthy nature of the campaign described.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Advanced persistent threat (APT)
The scenario describes a threat actor that maintained stealthy, long-term access to a network, moved laterally, and exfiltrated data over six months using custom malware that evaded antivirus. This aligns with the definition of an Advanced Persistent Threat (APT), which is a sophisticated, well-resourced adversary that conducts prolonged, targeted campaigns to achieve specific objectives, often espionage or data theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Insider threat
Why it's wrong here
While insider threats can cause long‑term damage, they originate from individuals with legitimate access (e.g., employees or contractors). The scenario describes an external attacker moving laterally, not an insider abusing granted privileges. Therefore, this option is incorrect.
When this WOULD be correct
This option would be correct in a scenario where a disgruntled employee uses their legitimate credentials to access sensitive data over several months, or where an employee unknowingly installs malware via a phishing email that leads to lateral movement, but the key is that the initial access is granted through insider status.
- ✓
Advanced persistent threat (APT)
Why this is correct
APT correctly describes a threat actor that establishes a long‑term presence, uses custom malware, and conducts lateral movement and data exfiltration—all of which are present in the scenario. APTs are designed to remain undetected while achieving strategic goals over months or years.
- ✗
Zero‑day exploit
Why it's wrong here
A zero‑day exploit refers to an attack that takes advantage of an unknown vulnerability before a patch is available. While an APT might use a zero‑day exploit as part of its toolkit, the scenario describes the overall campaign (persistence, lateral movement, exfiltration), not a single exploit. Thus, this option is too narrow.
When this WOULD be correct
A zero-day exploit would be the correct answer if the question described a threat actor using a previously unknown vulnerability to gain initial access, with no mention of long-term persistence, lateral movement, or custom malware.
- ✗
Denial of service (DoS) attack
Why it's wrong here
A denial-of-service (DoS) attack aims to disrupt the availability of a system by overwhelming it with traffic, exhausting resources, or exploiting a single point of failure—typically causing an immediate, high-impact outage. In this scenario, the attacker maintained persistent, stealthy access and performed lateral movement and data exfiltration, which are actions against confidentiality and integrity, not availability. Furthermore, DoS attacks are usually short-lived and overt, whereas the described campaign is long-term and covert, making this option fundamentally incompatible with the observed behavior.
When this WOULD be correct
A question describing a sudden network outage caused by overwhelming traffic from a single source, with no evidence of data theft or lateral movement, would make DoS the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Advanced persistent threat (APT)Correct answer▾
Why this is correct
APT correctly describes a threat actor that establishes a long‑term presence, uses custom malware, and conducts lateral movement and data exfiltration—all of which are present in the scenario. APTs are designed to remain undetected while achieving strategic goals over months or years.
✗Insider threatWrong answer — click to see why▾
Why this is wrong here
The scenario describes an external attacker using custom malware to evade detection and maintain long-term access, which is characteristic of an APT, not an insider threat. An insider threat would involve a person with authorized access, such as an employee or contractor, misusing their privileges.
★ When this WOULD be the correct answer
This option would be correct in a scenario where a disgruntled employee uses their legitimate credentials to access sensitive data over several months, or where an employee unknowingly installs malware via a phishing email that leads to lateral movement, but the key is that the initial access is granted through insider status.
Why candidates choose this
Candidates may confuse the long duration and lateral movement with an insider's ability to move freely, overlooking that the attacker used custom malware and backdoors, which are typical of external APT groups rather than insiders.
✗Zero‑day exploitWrong answer — click to see why▾
Why this is wrong here
A zero-day exploit refers to a vulnerability that is unknown to the vendor and has no patch, but the question describes custom malware that evaded antivirus and maintained persistence over six months, which is characteristic of an APT campaign, not a single exploit.
★ When this WOULD be the correct answer
A zero-day exploit would be the correct answer if the question described a threat actor using a previously unknown vulnerability to gain initial access, with no mention of long-term persistence, lateral movement, or custom malware.
Why candidates choose this
Candidates may confuse the use of custom malware that evades antivirus with a zero-day exploit, as both involve advanced techniques that bypass traditional defenses.
✗Denial of service (DoS) attackWrong answer — click to see why▾
Why this is wrong here
A denial of service (DoS) attack aims to disrupt service availability, not to maintain persistent access, move laterally, or exfiltrate data over six months.
★ When this WOULD be the correct answer
A question describing a sudden network outage caused by overwhelming traffic from a single source, with no evidence of data theft or lateral movement, would make DoS the correct answer.
Why candidates choose this
Candidates may confuse any malicious activity with a DoS attack, or they might think that the attacker's persistence involves overwhelming defenses, but DoS is about availability, not stealthy access.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.