GCIH · Question #332
Which control could help detect insider abuse of an organization's intellectual property?
The correct answer is A. Encryption in transit. Monitoring data in transit with DLP-integrated inspection allows an organization to detect when an insider is exfiltrating intellectual property across the network perimeter.
Question
Which control could help detect insider abuse of an organization's intellectual property?
Options
- AEncryption in transit
- BDigital signatures
- CWhole disk encryption
- DStrong passwords
How the community answered
(45 responses)- A84% (38)
- B4% (2)
- C2% (1)
- D9% (4)
Why each option
Monitoring data in transit with DLP-integrated inspection allows an organization to detect when an insider is exfiltrating intellectual property across the network perimeter.
Encryption in transit, when paired with Data Loss Prevention solutions that perform SSL/TLS inspection, enables real-time monitoring of outbound data flows for sensitive content. This acts as a detective control by triggering alerts when confidential intellectual property is transmitted to unauthorized external destinations, directly identifying insider exfiltration attempts.
Digital signatures verify integrity and non-repudiation of documents but do not actively monitor or alert on unauthorized transmission of intellectual property.
Whole disk encryption protects data at rest from physical theft but provides no visibility into what an authenticated insider copies or transmits over the network.
Strong passwords are a preventive authentication control that limits initial access but cannot detect or alert on misuse after an insider has already authenticated.
Concept tested: Detective controls for insider threat and intellectual property exfiltration
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.