nerdexam
EC-Council

112-52 · Question #75

Which of the following is a strong indicator of a potential insider threat?

The correct answer is A. Increased data usage. Increased data usage (A) is a strong indicator of a potential insider threat because it may signal that an employee is exfiltrating large volumes of sensitive data - downloading files in bulk, transferring data to external drives, or accessing systems outside their normal scope.

Attacks and Countermeasures

Question

Which of the following is a strong indicator of a potential insider threat?

Options

  • AIncreased data usage
  • BConsistent adherence to security policies
  • CPrompt reporting of suspicious activity
  • DRegular participation in security training

How the community answered

(43 responses)
  • A
    86% (37)
  • B
    7% (3)
  • C
    5% (2)
  • D
    2% (1)

Explanation

Increased data usage (A) is a strong indicator of a potential insider threat because it may signal that an employee is exfiltrating large volumes of sensitive data - downloading files in bulk, transferring data to external drives, or accessing systems outside their normal scope.

B (Consistent adherence to security policies) is incorrect because following the rules is exactly what a trustworthy employee does - it's the absence of policy adherence that raises flags. C (Prompt reporting of suspicious activity) is the opposite of a threat indicator; it demonstrates security-conscious behavior and is actively encouraged. D (Regular participation in security training) similarly reflects good security culture, not malicious intent.

Memory tip: Think "insiders hide and hoard" - unusual data hoarding (spikes in downloads/transfers) is the tell, while behaviors like reporting and training are hallmarks of a helpful insider, not a harmful one.

Topics

#insider threats#behavioral indicators#data exfiltration#threat detection

Community Discussion

No community discussion yet for this question.

Full 112-52 Practice