112-52 · Question #75
Which of the following is a strong indicator of a potential insider threat?
The correct answer is A. Increased data usage. Increased data usage (A) is a strong indicator of a potential insider threat because it may signal that an employee is exfiltrating large volumes of sensitive data - downloading files in bulk, transferring data to external drives, or accessing systems outside their normal scope.
Question
Which of the following is a strong indicator of a potential insider threat?
Options
- AIncreased data usage
- BConsistent adherence to security policies
- CPrompt reporting of suspicious activity
- DRegular participation in security training
How the community answered
(43 responses)- A86% (37)
- B7% (3)
- C5% (2)
- D2% (1)
Explanation
Increased data usage (A) is a strong indicator of a potential insider threat because it may signal that an employee is exfiltrating large volumes of sensitive data - downloading files in bulk, transferring data to external drives, or accessing systems outside their normal scope.
B (Consistent adherence to security policies) is incorrect because following the rules is exactly what a trustworthy employee does - it's the absence of policy adherence that raises flags. C (Prompt reporting of suspicious activity) is the opposite of a threat indicator; it demonstrates security-conscious behavior and is actively encouraged. D (Regular participation in security training) similarly reflects good security culture, not malicious intent.
Memory tip: Think "insiders hide and hoard" - unusual data hoarding (spikes in downloads/transfers) is the tell, while behaviors like reporting and training are hallmarks of a helpful insider, not a harmful one.
Topics
Community Discussion
No community discussion yet for this question.