nerdexam
CompTIA

CAS-001 · Question #39

A database is hosting information assets with a computed CIA aggregate value of high. The database is located within a secured network zone where there is flow control between the client and…

The correct answer is A. Inappropriate administrator access. With strong network perimeter controls (secured zone with flow control) in place, external threats like malicious code delivered over the network are largely mitigated. The most likely remaining threat is inappropriate administrator access (A). Administrators have privileged…

Enterprise Security

Question

A database is hosting information assets with a computed CIA aggregate value of high. The database is located within a secured network zone where there is flow control between the client and datacenter networks. Which of the following is the MOST likely threat?

Options

  • AInappropriate administrator access
  • BMalicious code
  • CInternal business fraud
  • DRegulatory compliance

How the community answered

(67 responses)
  • A
    58% (39)
  • B
    6% (4)
  • C
    25% (17)
  • D
    10% (7)

Explanation

With strong network perimeter controls (secured zone with flow control) in place, external threats like malicious code delivered over the network are largely mitigated. The most likely remaining threat is inappropriate administrator access (A). Administrators have privileged, often unrestricted access to the database and can bypass many security controls. The network segmentation does not prevent insiders with legitimate credentials from abusing their access. Malicious code (B) is less likely because the network controls restrict inbound traffic. Internal business fraud (C) is possible but typically requires the same elevated access that administrators already possess, making administrative misuse the more precise threat category. Regulatory compliance (D) is a governance concern, not a threat to the CIA triad.

Topics

#privileged access#database security#insider threat#threat analysis

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice