CAS-005 · Question #330
A security analyst is investigating a possible insider threat incident that involves the use of an unauthorized USB from a shared account to exfiltrate data. The event did not create an alert. The ana
Sign in or unlock CAS-005 to reveal the answer and full explanation for question #330. The question stem and answer options stay visible for context.
Question
A security analyst is investigating a possible insider threat incident that involves the use of an unauthorized USB from a shared account to exfiltrate data. The event did not create an alert. The analyst has confirmed the USB hardware ID is not on the device allow list, but has not yet confirmed the owner of the USB device. Which of the following actions should the analyst take next?
Options
- AClassify the incident as a false positive.
- BClassify the incident as a false negative.
- CClassify the incident as a true positive.
- DClassify the incident as a true negative.
Unlock CAS-005 to see the answer
You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.