312-50V13 · Question #607
A multinational organization has recently faced a severe information security breach. Investigations reveal that the attacker had a high degree of understanding of the organization's internal…
The correct answer is A. Insider attacks and the organization should have implemented robust access control and. The described breach, where an attacker leveraged a high degree of understanding of internal processes to bypass controls and corrupt resources, points to an insider attack, which can be counteracted with robust access control.
Question
Options
- AInsider attacks and the organization should have implemented robust access control and
- BDistribution attack and the organization could have ensured software and hardware integrity
- CPassive attack and the organization should have used encryption techniques.
- DActive attack and the organization could have used network traffic analysis.
How the community answered
(49 responses)- A76% (37)
- B14% (7)
- C4% (2)
- D6% (3)
Why each option
The described breach, where an attacker leveraged a high degree of understanding of internal processes to bypass controls and corrupt resources, points to an insider attack, which can be counteracted with robust access control.
An attacker possessing a 'high degree of understanding of the organization's internal processes and systems' to bypass security controls and corrupt resources is a clear indicator of an insider threat. To counter this, implementing robust access control measures-such as the principle of least privilege, strict authentication, and continuous monitoring of user activities-is essential to restrict access to only what is necessary and detect anomalous behavior from within.
A distribution attack involves tampering with software or hardware during its distribution to target systems, which does not align with an attacker having deep internal process knowledge and directly bypassing controls within an existing system.
A passive attack involves eavesdropping or monitoring without altering data or systems; the scenario describes active actions like 'bypassed security controls and corrupted valuable resources,' ruling out a passive attack.
While the breach was an active attack, network traffic analysis is primarily a detection and forensic tool; robust access control is a more direct preventative countermeasure against an attacker leveraging internal knowledge as described.
Concept tested: Insider threat mitigation, access control principles
Source: https://learn.microsoft.com/en-us/security/compass/incident-response-playbook-insider-threat
Topics
Community Discussion
No community discussion yet for this question.