An advanced actor spends months mapping a power utility's IT network before touching OT, leaving no ransom note and making no demands. Which motive is most consistent?
- A.Pre-positioning for a future disruptive capability
- B.Embarrassing the utility on social media
- C.Testing the firm's published disclosure policy
- D.Quick monetization through resale of credentials
Why A is correct
Long quiet reconnaissance with no demands is typical of pre-positioning by a capable state-aligned actor so the option to disrupt exists later. Credential resale is fast and noisy, publicity seekers announce themselves, and policy testing is not an attacker motive here.
Know someone studying for OT Security Fundamentals? Send them this one.