GCIH · Question #409
A company requires employees to sign an acknowledgement of the organization's security policy when they are hired. An employee with email access used the company's mail server to transmit harassing…
The correct answer is A. Unauthorized use. An employee who uses company systems for purposes outside the scope of their authorization - even with valid credentials - commits unauthorized use under the acceptable-use policy they signed.
Question
A company requires employees to sign an acknowledgement of the organization's security policy when they are hired. An employee with email access used the company's mail server to transmit harassing emails to an ex-coworker with spoofed sender addresses. Which of the following describes this incident?
Options
- AUnauthorized use
- BAuthentication bypass
- CData breach
- DSocial engineering
How the community answered
(17 responses)- A94% (16)
- D6% (1)
Why each option
An employee who uses company systems for purposes outside the scope of their authorization - even with valid credentials - commits unauthorized use under the acceptable-use policy they signed.
The employee had legitimate access to the mail server but used it to transmit harassing emails with spoofed sender addresses, which is clearly outside any sanctioned business purpose. The signed security policy acknowledgement establishes the boundary of acceptable use, and exceeding that boundary with the company's resources constitutes unauthorized use regardless of whether the employee held valid credentials.
Authentication bypass involves circumventing or subverting login controls to gain access without proper credentials; the employee used their own legitimate credentials and bypassed nothing.
A data breach involves the unauthorized exposure, exfiltration, or disclosure of sensitive data; no confidential information was accessed or leaked in this incident.
Social engineering involves psychologically manipulating individuals into divulging information or performing actions; sending harassing emails does not involve deceiving someone to gain information or access.
Concept tested: Unauthorized use of company IT resources and acceptable-use policy
Source: https://csrc.nist.gov/glossary/term/unauthorized_access
Topics
Community Discussion
No community discussion yet for this question.