nerdexam
CompTIA

SY0-701 · Question #28

An administrator was notified that a user logged in remotely after hours and copied large amounts of data to a personal device. Which of the following best describes the user's activity?

The correct answer is D. Insider threat. An insider threat is a security risk that originates from within the organization, such as an employee, contractor, or business partner, who has authorized access to the organization's data and systems. An insider threat can be malicious, such as stealing, leaking, or…

Submitted by fatema_kw· Mar 6, 2026Threats, vulnerabilities, and mitigations

Question

An administrator was notified that a user logged in remotely after hours and copied large amounts of data to a personal device. Which of the following best describes the user's activity?

Options

  • APenetration testing
  • BPhishing campaign
  • CExternal audit
  • DInsider threat

How the community answered

(64 responses)
  • A
    2% (1)
  • B
    9% (6)
  • C
    3% (2)
  • D
    86% (55)

Explanation

An insider threat is a security risk that originates from within the organization, such as an employee, contractor, or business partner, who has authorized access to the organization's data and systems. An insider threat can be malicious, such as stealing, leaking, or sabotaging sensitive data, or unintentional, such as falling victim to phishing or social engineering. An insider threat can cause significant damage to the organization's reputation, finances, operations, and legal compliance. The user's activity of logging in remotely after hours and copying large amounts of data to a personal device is an example of a malicious insider threat, as it violates the organization's security policies and compromises the confidentiality and integrity of the data.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice