nerdexam
EC-Council

312-50V13 · Question #607

A multinational organization has recently faced a severe information security breach. Investigations reveal that the attacker had a high degree of understanding of the organization's internal…

The correct answer is A. Insider attacks and the organization should have implemented robust access control and. The described breach, where an attacker leveraged a high degree of understanding of internal processes to bypass controls and corrupt resources, points to an insider attack, which can be counteracted with robust access control.

Submitted by stefanr· Mar 6, 2026System Hacking

Question

A multinational organization has recently faced a severe information security breach. Investigations reveal that the attacker had a high degree of understanding of the organization's internal processes and systems. This knowledge was utilized to bypass security controls and corrupt valuable resources. Considering this event, the security team is contemplating the type of attack that occurred and the steps they could have taken to prevent it. Choose the most plausible type of attack and a countermeasure that the organization could have employed:

Options

  • AInsider attacks and the organization should have implemented robust access control and
  • BDistribution attack and the organization could have ensured software and hardware integrity
  • CPassive attack and the organization should have used encryption techniques.
  • DActive attack and the organization could have used network traffic analysis.

How the community answered

(49 responses)
  • A
    76% (37)
  • B
    14% (7)
  • C
    4% (2)
  • D
    6% (3)

Why each option

The described breach, where an attacker leveraged a high degree of understanding of internal processes to bypass controls and corrupt resources, points to an insider attack, which can be counteracted with robust access control.

AInsider attacks and the organization should have implemented robust access control andCorrect

An attacker possessing a 'high degree of understanding of the organization's internal processes and systems' to bypass security controls and corrupt resources is a clear indicator of an insider threat. To counter this, implementing robust access control measures-such as the principle of least privilege, strict authentication, and continuous monitoring of user activities-is essential to restrict access to only what is necessary and detect anomalous behavior from within.

BDistribution attack and the organization could have ensured software and hardware integrity

A distribution attack involves tampering with software or hardware during its distribution to target systems, which does not align with an attacker having deep internal process knowledge and directly bypassing controls within an existing system.

CPassive attack and the organization should have used encryption techniques.

A passive attack involves eavesdropping or monitoring without altering data or systems; the scenario describes active actions like 'bypassed security controls and corrupted valuable resources,' ruling out a passive attack.

DActive attack and the organization could have used network traffic analysis.

While the breach was an active attack, network traffic analysis is primarily a detection and forensic tool; robust access control is a more direct preventative countermeasure against an attacker leveraging internal knowledge as described.

Concept tested: Insider threat mitigation, access control principles

Source: https://learn.microsoft.com/en-us/security/compass/incident-response-playbook-insider-threat

Topics

#insider threat#access control#security breach#data corruption

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice