nerdexam
GIAC

GCIH · Question #332

Which control could help detect insider abuse of an organization's intellectual property?

The correct answer is A. Encryption in transit. Monitoring data in transit with DLP-integrated inspection allows an organization to detect when an insider is exfiltrating intellectual property across the network perimeter.

Incident Response & Cyber Kill Chain

Question

Which control could help detect insider abuse of an organization's intellectual property?

Options

  • AEncryption in transit
  • BDigital signatures
  • CWhole disk encryption
  • DStrong passwords

How the community answered

(45 responses)
  • A
    84% (38)
  • B
    4% (2)
  • C
    2% (1)
  • D
    9% (4)

Why each option

Monitoring data in transit with DLP-integrated inspection allows an organization to detect when an insider is exfiltrating intellectual property across the network perimeter.

AEncryption in transitCorrect

Encryption in transit, when paired with Data Loss Prevention solutions that perform SSL/TLS inspection, enables real-time monitoring of outbound data flows for sensitive content. This acts as a detective control by triggering alerts when confidential intellectual property is transmitted to unauthorized external destinations, directly identifying insider exfiltration attempts.

BDigital signatures

Digital signatures verify integrity and non-repudiation of documents but do not actively monitor or alert on unauthorized transmission of intellectual property.

CWhole disk encryption

Whole disk encryption protects data at rest from physical theft but provides no visibility into what an authenticated insider copies or transmits over the network.

DStrong passwords

Strong passwords are a preventive authentication control that limits initial access but cannot detect or alert on misuse after an insider has already authenticated.

Concept tested: Detective controls for insider threat and intellectual property exfiltration

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

Topics

#insider threat#DLP#data exfiltration detection#access monitoring

Community Discussion

No community discussion yet for this question.

Full GCIH Practice