A hacktivist group posts screenshots of an internet-exposed water plant HMI that still uses its default password. What is the usual goal of such an actor?
- A.Settling a grievance with a former employer
- B.Gaining public attention for a political cause
- C.Stealing process designs for a foreign ministry
- D.Encrypting servers to demand a ransom payment
Why B is correct
Hacktivists want visibility and a message, so exposed and weakly protected HMIs are attractive trophies. Intelligence gathering fits a state actor, encryption for payment fits a criminal ransomware crew, and a personal grievance fits an insider.
Know someone studying for OT Security Fundamentals? Send them this one.