A Chief Information Security Officer (CISO) wants to explicitly raise awareness about the increase of ransomware-as-a-service in a report to the management team. Which of the following best describes the threat actor in the CISO’s report?
Choose an answer
Tap an option to check your answer.
Correct answer: Organized crime.
Why this is the answer
Organized crime is the most fitting description because ransomware-as-a-service (RaaS) operations are typically run by sophisticated, financially motivated criminal groups. These groups develop ransomware and lease it to affiliates, focusing on profit generation. Insider threats are individuals within an organization, not external RaaS providers. Hacktivists are motivated by political or social causes, not primarily financial gain through RaaS. Nation-state actors often engage in espionage or critical infrastructure attacks, but while they might use ransomware, the as-a-service model is predominantly a hallmark of financially driven organized crime.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed