SY0-701 · Question #561
An organization needs to monitor its users' activities in order to prevent insider threats. Which of the following solutions would help the organization achieve this goal?
The correct answer is A. Behavioral analytics. Behavioral analytics is correct because it establishes baselines of normal user activity and flags deviations - such as unusual login times, abnormal data access patterns, or privilege misuse - which are the hallmarks of insider threat detection. Access control lists (B) restrict
Question
An organization needs to monitor its users' activities in order to prevent insider threats. Which of the following solutions would help the organization achieve this goal?
Options
- ABehavioral analytics
- BAccess control lists
- CIdentity and access management
- DNetwork intrusion detection system
How the community answered
(34 responses)- A85% (29)
- B3% (1)
- C9% (3)
- D3% (1)
Explanation
Behavioral analytics is correct because it establishes baselines of normal user activity and flags deviations - such as unusual login times, abnormal data access patterns, or privilege misuse - which are the hallmarks of insider threat detection.
Access control lists (B) restrict what users can access, but don't monitor or analyze how they behave once access is granted. Identity and access management (C) manages authentication and authorization (who gets in and what they can do), not behavioral surveillance. Network intrusion detection systems (D) watch for external attacks and anomalous network traffic, not the day-to-day actions of legitimate, credentialed insiders.
Memory tip: Think "insider = behavior." Insiders already have access, so tools that control or detect access (ACLs, IAM, NIDS) won't catch them - only a tool that watches behavior will.
Topics
Community Discussion
No community discussion yet for this question.