nerdexam
GIAC

GSEC · Question #210

Which of the following groups represents the most likely source of an asset loss through the inappropriate use of computers?

The correct answer is C. Employees. Employees represent the greatest insider threat for asset loss because they have legitimate, trusted access to organizational systems and data.

Incident Handling, Risk, and Governance

Question

Which of the following groups represents the most likely source of an asset loss through the inappropriate use of computers?

Options

  • AVisitors
  • BCustomers
  • CEmployees
  • DHackers

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    5% (2)
  • C
    78% (29)
  • D
    14% (5)

Why each option

Employees represent the greatest insider threat for asset loss because they have legitimate, trusted access to organizational systems and data.

AVisitors

Visitors typically have very limited or no access to internal computer systems, significantly reducing their ability to misuse assets.

BCustomers

Customers generally interact only with public-facing systems and services, not internal assets, limiting their exposure and opportunity for misuse.

CEmployeesCorrect

Employees already have authorized access to internal networks, systems, and sensitive data, making inappropriate use far easier and harder to detect than external attacks. Insider threats - whether malicious or accidental - consistently rank as the leading cause of organizational data loss in security studies. Their privileged access and knowledge of internal controls gives them a significant advantage over outside parties.

DHackers

Hackers are an external threat and must overcome security barriers to gain access, making them a significant but less statistically common source of loss compared to insiders with pre-existing access.

Concept tested: Insider threat as primary source of asset loss

Source: https://www.cisa.gov/topics/physical-security/insider-threat-mitigation

Topics

#insider threat#asset loss#employee risk#security policy

Community Discussion

No community discussion yet for this question.

Full GSEC Practice