CAS-002 · Question #608
A database is hosting information assets with a computed CIA aggregate value of high. The database is located within a secured network zone where there is flow control between the client and…
The correct answer is A. Inappropriate administrator access. In a secured network zone with flow controls limiting external access, insider threats - specifically inappropriate privileged access by database administrators - represent the most likely residual threat to a high CIA-value asset.
Question
A database is hosting information assets with a computed CIA aggregate value of high. The database is located within a secured network zone where there is flow control between the client and datacenter networks. Which of the following is the MOST likely threat?
Options
- AInappropriate administrator access
- BMalicious code
- CInternal business fraud
- DRegulatory compliance
How the community answered
(60 responses)- A43% (26)
- B15% (9)
- C33% (20)
- D8% (5)
Why each option
In a secured network zone with flow controls limiting external access, insider threats - specifically inappropriate privileged access by database administrators - represent the most likely residual threat to a high CIA-value asset.
When a database resides in a secured zone with network flow controls between the client and datacenter networks, external threats and lateral movement are significantly mitigated by the perimeter architecture. Database administrators hold privileged, direct access that bypasses many technical controls, making inappropriate administrative access the most probable residual threat. High CIA-value assets are prime targets for insiders with elevated privileges who are already trusted by the network controls in place.
Malicious code introduction is less likely because the secured zone and flow controls reduce the attack surface and limit pathways through which code could be delivered to the database.
Internal business fraud typically refers to financial manipulation at the business process layer and is not the most direct technical threat vector against a secured database system.
Regulatory compliance is an obligation or requirement, not a threat; it cannot directly compromise the confidentiality, integrity, or availability of the database.
Concept tested: Insider threat identification for privileged database access
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.