nerdexam
GIAC

GCIA · Question #53

You work as a Network Security Administrator for NetPerfect Inc. The company has a Windowsbased network. You are incharge of the data and network security of the company. While performing a threat log

The correct answer is C. Internal threat. A database administrator stealing confidential data from within the organization is classified as an internal threat because the actor is an authorized insider misusing their access privileges.

Threat Intelligence & Network Security Monitoring

Question

You work as a Network Security Administrator for NetPerfect Inc. The company has a Windowsbased network. You are incharge of the data and network security of the company. While performing a threat log analysis, you observe that one of the database administrators is pilfering confidential data. What type of threat is this?

Options

  • AZombie
  • BExternal threat
  • CInternal threat
  • DMalware

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    71% (22)
  • D
    19% (6)

Why each option

A database administrator stealing confidential data from within the organization is classified as an internal threat because the actor is an authorized insider misusing their access privileges.

AZombie

A zombie refers to a compromised machine controlled remotely by an attacker, not a human insider intentionally stealing data.

BExternal threat

An external threat originates from outside the organization's network perimeter, such as a hacker or competitor, whereas this actor is an internal employee with authorized access.

CInternal threatCorrect

An internal threat originates from individuals who already have authorized access to organizational systems, such as employees, contractors, or administrators. In this scenario, the database administrator has legitimate system access and is exploiting that position to pilfer confidential data. This distinguishes it from external threats because no perimeter breach is required.

DMalware

Malware refers to malicious software such as viruses or ransomware, not a human actor deliberately exfiltrating data.

Concept tested: Insider threat classification and identification

Source: https://www.cisa.gov/topics/physical-security/insider-threat-mitigation

Topics

#insider threat#internal threat#threat classification#data exfiltration

Community Discussion

No community discussion yet for this question.

Full GCIA Practice