312-49V11 · Question #14
Sophia, a cybersecurity analyst, is investigating a data breach within a company. The breach is suspected to have come from an insider, as sensitive company data was altered from within the…
The correct answer is D. The attacker had legitimate access to the company's internal systems and data. This scenario aligns with CHFI v11 objectives under Computer Forensics Fundamentals and Insider Threat and Identity Theft Forensics. One of the defining characteristics of an insider threat is that the attacker already possesses authorized or legitimate access to internal…
Question
Sophia, a cybersecurity analyst, is investigating a data breach within a company. The breach is suspected to have come from an insider, as sensitive company data was altered from within the company's network. Sophia needs to determine whether the breach was caused by an insider (someone within the company) or an external attacker (someone from outside the company). Which of the following factors would most likely indicate that the breach was carried out by an insider?
Options
- AThe attack used advanced social engineering tactics to exploit external vulnerabilities.
- BThe attack was launched from a known external IP address associated with a hacker group.
- CThe attacker used a distributed denial-of-service (DDoS) attack to overwhelm the network.
- DThe attacker had legitimate access to the company's internal systems and data.
How the community answered
(58 responses)- A7% (4)
- B16% (9)
- C3% (2)
- D74% (43)
Explanation
This scenario aligns with CHFI v11 objectives under Computer Forensics Fundamentals and Insider Threat and Identity Theft Forensics. One of the defining characteristics of an insider threat is that the attacker already possesses authorized or legitimate access to internal systems, applications, or sensitive data. CHFI v11 emphasizes that insider attacks often bypass perimeter defenses because the malicious activity originates from trusted accounts, internal IP ranges, or authenticated sessions. If sensitive data is altered from within the organization's network using valid credentials, it strongly suggests insider involvement. Insiders may include disgruntled employees, contractors, or partners who misuse their access privileges intentionally or unintentionally. This type of breach is often detected through anomalies in user behavior, access logs, privilege misuse, or violations of least-privilege principles.
Topics
Community Discussion
No community discussion yet for this question.