CAS-002 · Question #643
John is concerned about internal security threats on the network he administers. He believes that he has taken every reasonable precaution against external threats, but is concerned that he may have…
The correct answer is A. Employees not following security policy. Employees may disregard policies, such as policies limiting the use of USB devices or the ability to download programs from the internet. This is the most pervasive internal security threat. Answer option D is incorrect. Employees selling sensitive data is, of course, possible…
Question
John is concerned about internal security threats on the network he administers. He believes that he has taken every reasonable precaution against external threats, but is concerned that he may have gaps in his internal security. Which of the following is the most likely internal threat?
Options
- AEmployees not following security policy
- BPrivilege Escalation
- CSQL Injection
- DEmployees selling sensitive data
How the community answered
(42 responses)- A81% (34)
- B7% (3)
- C2% (1)
- D10% (4)
Explanation
Employees may disregard policies, such as policies limiting the use of USB devices or the ability to download programs from the internet. This is the most pervasive internal security threat. Answer option D is incorrect. Employees selling sensitive data is, of course, possible. However, this scenario is less likely that option A. Answer option C is incorrect. SQL Injection is most likely accomplished by an external hacker. Answer option B is incorrect. Privilege escalation can be done by internal or external attackers. However, even with internal attackers, it is far less likely than option B.
Topics
Community Discussion
No community discussion yet for this question.