nerdexam
CompTIA

SY0-701 · Question #561

An organization needs to monitor its users' activities in order to prevent insider threats. Which of the following solutions would help the organization achieve this goal?

The correct answer is A. Behavioral analytics. Behavioral analytics is correct because it establishes baselines of normal user activity and flags deviations - such as unusual login times, abnormal data access patterns, or privilege misuse - which are the hallmarks of insider threat detection. Access control lists (B) restrict

Submitted by neha2k· Mar 6, 2026Threats, vulnerabilities, and mitigations

Question

An organization needs to monitor its users' activities in order to prevent insider threats. Which of the following solutions would help the organization achieve this goal?

Options

  • ABehavioral analytics
  • BAccess control lists
  • CIdentity and access management
  • DNetwork intrusion detection system

How the community answered

(34 responses)
  • A
    85% (29)
  • B
    3% (1)
  • C
    9% (3)
  • D
    3% (1)

Explanation

Behavioral analytics is correct because it establishes baselines of normal user activity and flags deviations - such as unusual login times, abnormal data access patterns, or privilege misuse - which are the hallmarks of insider threat detection.

Access control lists (B) restrict what users can access, but don't monitor or analyze how they behave once access is granted. Identity and access management (C) manages authentication and authorization (who gets in and what they can do), not behavioral surveillance. Network intrusion detection systems (D) watch for external attacks and anomalous network traffic, not the day-to-day actions of legitimate, credentialed insiders.

Memory tip: Think "insider = behavior." Insiders already have access, so tools that control or detect access (ACLs, IAM, NIDS) won't catch them - only a tool that watches behavior will.

Topics

#Behavioral analytics#Insider threats#User activity monitoring#Threat mitigation

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice