nerdexam
EC-Council

212-89 · Question #6

An insider threat response plan helps an organization minimize the damage caused by malicious insiders. One of the approaches to mitigate these threats is setting up controls from the human…

The correct answer is A. Access granted to users should be documented and vetted by a supervisor. One of the key approaches to mitigating insider threats is ensuring that access control policies are strictly implemented and monitored. This includes the guideline that access granted to users should be thoroughly documented and vetted by a supervisor. This control helps…

Incident Handling and Response Planning

Question

An insider threat response plan helps an organization minimize the damage caused by malicious insiders. One of the approaches to mitigate these threats is setting up controls from the human resources department. Which of the following guidelines can the human resources department use?

Options

  • AAccess granted to users should be documented and vetted by a supervisor.
  • BDisable the default administrative account to ensure accountability.
  • CImplement a person-to-person rule to secure the backup process and physical media.
  • DMonitor and secure the organization's physical environment.

How the community answered

(36 responses)
  • A
    83% (30)
  • B
    8% (3)
  • C
    3% (1)
  • D
    6% (2)

Explanation

One of the key approaches to mitigating insider threats is ensuring that access control policies are strictly implemented and monitored. This includes the guideline that access granted to users should be thoroughly documented and vetted by a supervisor. This control helps ensure that users have only the access necessary to perform their job functions, reducing the risk of inappropriate access or misuse of information. Proper documentation and supervisor approval also ensure accountability and traceability of access decisions, which is crucial for detecting and responding to insider threats. The human resources department plays a vital role in this process, working closely with IT and security teams to enforce access control policies, conduct regular reviews of access rights, and manage the onboarding and offboarding process to ensure that access rights are appropriately updated.

Topics

#insider threat#HR controls#access control#mitigation guidelines

Community Discussion

No community discussion yet for this question.

Full 212-89 Practice