nerdexam
CompTIA

CS0-003 · Question #303

Which of the following best describes the threat concept in which an organization works to ensure that all network users only open attachments from known sources?

The correct answer is C. Unintentional insider threat. Unintentional Insider Threat Explained Training employees to only open attachments from known sources directly addresses the unintentional insider threat, where well-meaning staff inadvertently compromise security through actions like opening malicious email attachments…

Submitted by tom_us· Mar 6, 2026Security operations

Question

Which of the following best describes the threat concept in which an organization works to ensure that all network users only open attachments from known sources?

Options

  • AHacktivist threat
  • BAdvanced persistent threat
  • CUnintentional insider threat
  • DNation-state threat

How the community answered

(57 responses)
  • A
    5% (3)
  • B
    2% (1)
  • C
    91% (52)
  • D
    2% (1)

Explanation

Unintentional Insider Threat Explained

Training employees to only open attachments from known sources directly addresses the unintentional insider threat, where well-meaning staff inadvertently compromise security through actions like opening malicious email attachments (phishing) - not out of malice, but through carelessness or lack of awareness. This policy-driven, user-education approach is a classic countermeasure targeting human error from within the organization.

Why the distractors are wrong:

  • Hacktivist threat (A): Refers to external attackers motivated by political or social agendas - not mitigated by internal attachment policies
  • Advanced Persistent Threat (B): Involves sophisticated, long-term external attackers (often state-sponsored) who use stealthy intrusion techniques beyond simple email attachments
  • Nation-state threat (D): Refers to government-sponsored cyberattacks targeting other nations or organizations - an external, highly organized threat actor category

Memory Tip: Think of "unintentional insider" as the "oops" threat - it's your own employees accidentally causing harm. Whenever you see a question about user training, awareness policies, or accidental employee actions, think Unintentional Insider Threat. If the solution involves educating staff, the threat is coming from the inside by mistake.

Topics

#Insider threat#Threat concepts#Security awareness#User behavior

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice