CV0-002 · Question #536
A security analyst is reviewing logs and sees a former employee's account has been used to access critical information on a private cloud resource. The analyst examines firewall and IPS logs but does
The correct answer is D. Internal attack. The absence of external traffic in security logs, coupled with a former employee's account being used, strongly points to an insider threat.
Question
A security analyst is reviewing logs and sees a former employee's account has been used to access critical information on a private cloud resource. The analyst examines firewall and IPS logs but does not find traffic that is relevant to the breach. Which of the following is the MOST likely source of the compromise?
Options
- AExternal attack
- BInternal role change
- CExternal privilege escalation
- DInternal attack
How the community answered
(24 responses)- A13% (3)
- B4% (1)
- C21% (5)
- D63% (15)
Why each option
The absence of external traffic in security logs, coupled with a former employee's account being used, strongly points to an insider threat.
An external attack would typically generate traffic detectable by firewalls or IPS, which the analyst explicitly stated was not found.
An internal attack is the most likely source of compromise because the use of a former employee's account to access critical information, without relevant external traffic being detected by firewalls or IPS, suggests that the access originated from within the organization's trusted network or that the credentials were misused by an internal actor.
Concept tested: Insider threats and security log analysis
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
Topics
Community Discussion
No community discussion yet for this question.