nerdexam
CompTIA

SY0-501 · Question #529

Joe, a salesman, was assigned to a new project that requires him to travel to a client site. While waiting for a flight, Joe decides to connect to the airport wireless network without connecting to…

The correct answer is A. Policy violation. The data breach most likely occurred because Joe violated company policy by sending confidential emails over an unsecure public Wi-Fi network without a VPN, leading to the interception of communications.

Submitted by lukas.cz· Mar 4, 2026Security program management and oversight

Question

Joe, a salesman, was assigned to a new project that requires him to travel to a client site. While waiting for a flight, Joe decides to connect to the airport wireless network without connecting to a VPN, and then sends confidential emails to fellow colleagues. A few days later, the company experiences a data breach. Upon investigation, the company learns Joe's emails were intercepted. Which of the following MOST likely caused the data breach?

Options

  • APolicy violation
  • BSocial engineering
  • CInsider threat
  • DZero--day attack

How the community answered

(38 responses)
  • A
    76% (29)
  • B
    5% (2)
  • C
    13% (5)
  • D
    5% (2)

Why each option

The data breach most likely occurred because Joe violated company policy by sending confidential emails over an unsecure public Wi-Fi network without a VPN, leading to the interception of communications.

APolicy violationCorrect

Joe's action of connecting to an airport wireless network without a VPN to send confidential emails directly violates common security policies that mandate secure communication channels for sensitive data, making this policy violation the most likely cause of the emails being intercepted and leading to the data breach. Companies typically enforce policies requiring VPN use when accessing company resources or handling sensitive information on untrusted networks to encrypt traffic and protect against eavesdropping.

BSocial engineering

Social engineering involves psychological manipulation to trick individuals into divulging information or performing actions, which is not what occurred as Joe intentionally chose to use an unsecure connection.

CInsider threat

While Joe is an insider, the scenario describes negligence leading to interception via an unsecure connection, rather than a malicious misuse of internal access or privileges, making policy violation a more precise cause.

DZero--day attack

A zero-day attack exploits a previously unknown software vulnerability, which is not indicated by the interception of emails over an unsecure public Wi-Fi network.

Concept tested: Security Policy Adherence and Secure Communication Practices

Source: https://learn.microsoft.com/en-us/compliance/regulatory/security-and-compliance-overview

Topics

#acceptable use policy#VPN#wireless security#policy violation

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice