nerdexam
Palo_Alto_Networks

PCCET · Question #177

In a Software-as-a-Service (SaaS) environment, which two data exposures result from well- intentioned end users? (Choose two.)

The correct answer is B. Promiscuous Share D. Malicious Insider. In a SaaS environment, data exposures often arise from users making unintentional errors in sharing and access management, or from their accounts being compromised due to poor security practices.

Submitted by cyberguy42· Apr 18, 2026Cloud Security

Question

In a Software-as-a-Service (SaaS) environment, which two data exposures result from well- intentioned end users? (Choose two.)

Options

  • AMalicious Outsider
  • BPromiscuous Share
  • CGhost Share
  • DMalicious Insider

How the community answered

(63 responses)
  • A
    5% (3)
  • B
    94% (59)
  • C
    2% (1)

Why each option

In a SaaS environment, data exposures often arise from users making unintentional errors in sharing and access management, or from their accounts being compromised due to poor security practices.

AMalicious Outsider

A malicious outsider is an external threat actor, not an exposure resulting from the actions of an internal, well-intentioned end user.

BPromiscuous ShareCorrect

A promiscuous share is a direct consequence of a well-intentioned end user inadvertently granting overly broad access permissions to sensitive data, leading to unauthorized exposure.

CGhost Share

A ghost share typically refers to persistent data access or orphaned permissions that are system-level issues or the result of poor governance, rather than a direct, active sharing decision by a well-intentioned end user.

DMalicious InsiderCorrect

A malicious insider scenario can result from a well-intentioned end user's actions, such as falling victim to social engineering or using weak credentials, which allows an attacker to compromise their account and operate as an insider.

Concept tested: SaaS data exposure risks from user behavior

Topics

#SaaS Security#Data Exposure#Insider Threat#Cloud Data Governance

Community Discussion

No community discussion yet for this question.

Full PCCET Practice