nerdexam
EC-Council

112-52 · Question #160

Which of the following is considered an insider threat?

The correct answer is A. A disgruntled employee transmitting confidential data to a competitor. Option A is correct because an insider threat originates from someone within the organization - in this case, a disgruntled employee who already has legitimate access to confidential data and abuses it by transmitting it to a competitor. Options B, C, and D are all external…

Attacks and Countermeasures

Question

Which of the following is considered an insider threat?

Options

  • AA disgruntled employee transmitting confidential data to a competitor
  • BA hacker exploiting a vulnerability in the firewall
  • CA malware infection from an email attachment
  • DA denial-of-service attack from an unknown external source

How the community answered

(23 responses)
  • A
    87% (20)
  • B
    9% (2)
  • C
    4% (1)

Explanation

Option A is correct because an insider threat originates from someone within the organization - in this case, a disgruntled employee who already has legitimate access to confidential data and abuses it by transmitting it to a competitor. Options B, C, and D are all external threats: a hacker exploiting a firewall vulnerability comes from outside the network perimeter, a malware infection via email attachment is an external payload delivered inbound, and a denial-of-service attack by definition originates from unknown outside actors. The key distinguishing factor is trust and access - insiders are people (employees, contractors, partners) who have been granted authorized access and misuse it, whereas external threats have no pre-existing legitimate access.

Memory tip: Think "INsider = INside the organization." If the threat actor already has keys to the building, it's an insider threat.

Topics

#Insider threats#Data exfiltration#Security threats#Employee misconduct

Community Discussion

No community discussion yet for this question.

Full 112-52 Practice