nerdexam
Cisco

350-201 · Question #119

A security manager received an email from an anomaly detection service, that one of their contractors has downloaded 50 documents from the company's confidential document management folder using a…

The correct answer is B. Report to the incident response team. A suspected insider threat involving bulk download of confidential data is a security incident that must be escalated to the incident response team, not investigated unilaterally by the security manager.

Processes

Question

A security manager received an email from an anomaly detection service, that one of their contractors has downloaded 50 documents from the company's confidential document management folder using a company- owned asset al039-ice-4ce687TL0500. A security manager reviewed the content of downloaded documents and noticed that the data affected is from different departments. What are the actions a security manager should take?

Options

  • AMeasure confidentiality level of downloaded documents.
  • BReport to the incident response team.
  • CEscalate to contractor's manager.
  • DCommunicate with the contractor to identify the motives.

How the community answered

(54 responses)
  • A
    6% (3)
  • B
    78% (42)
  • C
    4% (2)
  • D
    13% (7)

Why each option

A suspected insider threat involving bulk download of confidential data is a security incident that must be escalated to the incident response team, not investigated unilaterally by the security manager.

AMeasure confidentiality level of downloaded documents.

The confidentiality level is already established because the files reside in a folder designated as confidential; re-measuring it does not advance the incident response.

BReport to the incident response team.Correct

Bulk exfiltration of confidential documents by a contractor is a potential data breach or insider threat incident that exceeds the security manager's authority to resolve alone. Reporting to the IR team activates the formal incident response process, ensures proper evidence handling, and brings in personnel with investigative authority and forensic tools.

CEscalate to contractor's manager.

Escalating directly to the contractor's manager could alert the subject of the investigation, compromise evidence integrity, and violate proper chain-of-custody procedures.

DCommunicate with the contractor to identify the motives.

Communicating with the contractor before the IR team is engaged could tip off the suspect, allow evidence destruction, and undermine any subsequent legal or disciplinary action.

Concept tested: Insider threat escalation and IR team engagement

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#insider threat#data exfiltration#anomaly detection#incident escalation

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice