nerdexam
(ISC)2

SSCP · Question #1298

The most common source of attack against companies comes from:

The correct answer is A. Insiders. Insider threats are often cited as the most common and damaging source of attacks against companies due to their privileged access and inherent knowledge of internal systems and processes.

Submitted by lukas.cz· Apr 18, 2026Risk Identification, Monitoring and Analysis

Question

The most common source of attack against companies comes from:

Options

  • AInsiders
  • BHackers
  • CCrackers
  • DScript kiddies
  • ESpies

How the community answered

(54 responses)
  • A
    89% (48)
  • B
    4% (2)
  • C
    2% (1)
  • E
    6% (3)

Why each option

Insider threats are often cited as the most common and damaging source of attacks against companies due to their privileged access and inherent knowledge of internal systems and processes.

AInsidersCorrect

Insiders, including current or former employees, contractors, or business partners, often possess authorized access to internal systems, data, and physical locations. This existing access gives them a significant advantage, making them a common source of malicious activity or unintentional security breaches, as they can bypass many external perimeter defenses.

BHackers

Hackers, while a threat, typically refer to external actors who must breach external defenses first, unlike insiders who already have access.

CCrackers

Crackers are a specific type of malicious hacker, usually focused on breaking into systems or software, and are generally external threats.

DScript kiddies

Script kiddies are less sophisticated external attackers using pre-made tools, making them less likely to be the 'most common source' for targeted company attacks compared to insiders.

ESpies

Spies are typically external actors, often state-sponsored, who aim to steal secrets, but are not necessarily the most common source of all attacks against companies.

Concept tested: Insider threat prevalence

Source: https://www.cisa.gov/topics/organizational-resilience/insider-threat

Topics

#Insider threats#Threat sources#Risk management#Attack vectors

Community Discussion

No community discussion yet for this question.

Full SSCP Practice