212-89 · Question #135
Unusual logins, accessing sensitive information not used for the job role, and the use of personal external storage drives on company assets are all signs of which of the following?
The correct answer is C. Insider threat. Insider threat (C) describes malicious or negligent behavior by someone within an organization - an employee, contractor, or partner - who misuses their legitimate access. The behaviors listed (unusual logins, accessing data outside their role, using personal storage devices)…
Question
Unusual logins, accessing sensitive information not used for the job role, and the use of personal external storage drives on company assets are all signs of which of the following?
Options
- ASecurity breach
- BOver-working
- CInsider threat
- DLack of job rotation
How the community answered
(22 responses)- A5% (1)
- C91% (20)
- D5% (1)
Explanation
Insider threat (C) describes malicious or negligent behavior by someone within an organization - an employee, contractor, or partner - who misuses their legitimate access. The behaviors listed (unusual logins, accessing data outside their role, using personal storage devices) are classic indicators because they suggest data exfiltration or unauthorized snooping by someone who already has internal access.
Why the distractors are wrong:
- A (Security breach) is too broad - a breach is the outcome, not the behavioral pattern. These signs are pre-breach indicators, not the breach itself.
- B (Over-working) has no security meaning; it's a plausible-sounding distraction but describes workload, not threat behavior.
- D (Lack of job rotation) is a control weakness, not a threat indicator - job rotation is a preventive measure, not something you detect from login anomalies.
Memory tip: Think "insider = inside behavior." All three signs involve someone already inside the network doing things outside their normal scope - that's the hallmark of an insider threat, distinct from an external attacker who first has to break in.
Topics
Community Discussion
No community discussion yet for this question.