nerdexam
(ISC)2(ISC)2

SSCP · Question #1308

SSCP Question #1308: Real Exam Question with Answer & Explanation

The correct answer is A: Insiders. Insiders are often considered the most common source of attacks against companies due to their privileged access, knowledge of internal systems, and often overlooked monitoring. They pose a significant threat as they can exploit trusted positions.

Submitted by asante_acc· Apr 18, 2026Security Concepts and Practices

Question

The most common source of attack against companies comes from:

Options

  • AInsiders
  • BHackers
  • CCrackers
  • DScript kiddies
  • ESpies

Explanation

Insiders are often considered the most common source of attacks against companies due to their privileged access, knowledge of internal systems, and often overlooked monitoring. They pose a significant threat as they can exploit trusted positions.

Common mistakes.

  • B. "Hackers" is a broad term for external actors, but specific statistics often point to insiders as the most common source of successful attacks or data breaches due to their established access.
  • C. Crackers are malicious hackers, but still represent an external threat, whereas insiders leverage internal access.
  • D. Script kiddies typically lack advanced skills and are less likely to be the most common source of sophisticated or damaging attacks compared to insiders with specific targets and knowledge.
  • E. Spies (corporate or state-sponsored) represent a highly sophisticated threat, but are not as common a source of general attacks as disgruntled or negligent insiders.

Concept tested. Common sources of cyber attacks (insider threats)

Reference. https://www.cisa.gov/topics/cyber-threats-and-advisories/insider-threats

Topics

#Insider threat#Common attack sources#Security risks#Threat actors

Community Discussion

No community discussion yet for this question.

Full SSCP PracticeBrowse All SSCP Questions