nerdexam
CompTIA

CV0-002 · Question #536

A security analyst is reviewing logs and sees a former employee's account has been used to access critical information on a private cloud resource. The analyst examines firewall and IPS logs but does

The correct answer is D. Internal attack. The absence of external traffic in security logs, coupled with a former employee's account being used, strongly points to an insider threat.

Security

Question

A security analyst is reviewing logs and sees a former employee's account has been used to access critical information on a private cloud resource. The analyst examines firewall and IPS logs but does not find traffic that is relevant to the breach. Which of the following is the MOST likely source of the compromise?

Options

  • AExternal attack
  • BInternal role change
  • CExternal privilege escalation
  • DInternal attack

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    4% (1)
  • C
    21% (5)
  • D
    63% (15)

Why each option

The absence of external traffic in security logs, coupled with a former employee's account being used, strongly points to an insider threat.

AExternal attack

An external attack would typically generate traffic detectable by firewalls or IPS, which the analyst explicitly stated was not found.

BInternal role change
CExternal privilege escalation
DInternal attackCorrect

An internal attack is the most likely source of compromise because the use of a former employee's account to access critical information, without relevant external traffic being detected by firewalls or IPS, suggests that the access originated from within the organization's trusted network or that the credentials were misused by an internal actor.

Concept tested: Insider threats and security log analysis

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf

Topics

#Insider threat#Account compromise#Access control#Log analysis

Community Discussion

No community discussion yet for this question.

Full CV0-002 Practice