GCED · Question #52
GCED Question #52: Real Exam Question with Answer & Explanation
The correct answer is A. Classification of information assets helps identify data to protect.. A company needs to classify its information as a key step in valuing it and knowing where to focus its protection. Rotation of duties and separation of duties are both key elements in reducing the scope of information access and the ability to conceal malicious behavior. Separati
Question
Options
- AClassification of information assets helps identify data to protect.
- BSecurity awareness programs have a minimal impact on reducing the insider threat.
- CBoth detective and preventative controls prevent insider attacks.
- DRotation of duties makes an insider threat more likely.
- ESeparation of duties encourages one employee to control a great deal of information.
Explanation
A company needs to classify its information as a key step in valuing it and knowing where to focus its protection. Rotation of duties and separation of duties are both key elements in reducing the scope of information access and the ability to conceal malicious behavior. Separation of duties helps minimize "empire building" within a company, keeping one individual from controlling a great deal of information, reducing the insider threat. Security awareness programs can help other employees notice the signs of an insider attack and thus reduce the insider threat. Detection is a reactive method and only occurs after an attack occurs. Only preventative methods can stop or limit an attack.
Community Discussion
No community discussion yet for this question.