Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC Exam GCED Topic 3 Question 36 Discussion

Actual exam question for GIAC's GIAC Certified Enterprise Defender exam
Question #: 36
Topic #: 3
[All GIAC Certified Enterprise Defender Questions]

Which statement below is the MOST accurate about insider threat controls?

Show Suggested Answer Hide Answer
Suggested Answer: A

A company needs to classify its information as a key step in valuing it and knowing where to focus its protection.

Rotation of duties and separation of duties are both key elements in reducing the scope of information access and the ability to conceal malicious behavior.

Separation of duties helps minimize ''empire building'' within a company, keeping one individual from controlling a great deal of information, reducing the insider threat.

Security awareness programs can help other employees notice the signs of an insider attack and thus reduce the insider threat.

Detection is a reactive method and only occurs after an attack occurs. Only preventative methods can stop or limit an attack.


Contribute your Thoughts:

Dorothy
2 days ago
A) Classification of information assets helps identify data to protect.
upvoted 0 times
...
Leonora
24 days ago
I'm going with A). It's all about identifying the data that needs to be protected. That's the foundation for effective insider threat controls.
upvoted 0 times
...
Gertude
26 days ago
Haha, E) is a good one. Encouraging one employee to control a great deal of information? That's just asking for trouble. Talk about a recipe for disaster!
upvoted 0 times
...
Lavonna
27 days ago
D)? Seriously? Rotation of duties makes an insider threat more likely? That's just backwards. Separation of duties is where it's at, folks.
upvoted 0 times
...
Dominque
28 days ago
B) is just plain wrong. Security awareness programs are crucial for reducing the insider threat. How else are employees going to know what to look out for?
upvoted 0 times
...
Emelda
1 months ago
Hmm, I'm not so sure. I think C) is the best answer - both detective and preventative controls are important for preventing insider attacks. You need a multi-layered approach, you know?
upvoted 0 times
...
Stevie
1 months ago
Oh, this is a tricky one! I think the MOST accurate statement is A) - classification of information assets helps identify data to protect. That's key for mitigating insider threats, isn't it?
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77