Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 1 Question 21 Discussion

Over the last year, an organization's HR department has accessed data from its legal department on the last day of each month to create a monthly activity report. An engineer is analyzing suspicious activity alerted by a threat intelligence platform that an authorized user in the HR department has accessed legal data daily for the last week. The engineer pulled the network data from the legal department's shared folders and discovered above average-size data dumps. Which threat actor is implied from these artifacts?
C) malicious insider
A) privilege escalation
B) internal user errors
D) external exfiltration

Cisco 300-215 Exam - Topic 1 Question 21 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 21
Topic #: 1
[All 300-215 Questions]

Over the last year, an organization's HR department has accessed data from its legal department on the last day of each month to create a monthly activity report. An engineer is analyzing suspicious activity alerted by a threat intelligence platform that an authorized user in the HR department has accessed legal data daily for the last week. The engineer pulled the network data from the legal department's shared folders and discovered above average-size data dumps. Which threat actor is implied from these artifacts?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Lucia
10 months ago
Privilege escalation seems likely too, but the data dumps are a red flag!
upvoted 0 times
...
Twana
10 months ago
I’m not sure it’s a malicious insider; could just be user errors.
upvoted 0 times
...
Jacqueline
11 months ago
Wait, daily access to legal data? That's odd...
upvoted 0 times
...
Jerry
11 months ago
Definitely suspicious activity from someone in HR.
upvoted 0 times
...
Ammie
11 months ago
Sounds like a classic case of a malicious insider.
upvoted 0 times
...
Stephane
11 months ago
Hmm, this looks like a tricky one. I'll need to think through the different object types in Financial Services Cloud to determine the best fit for modeling a client.
upvoted 0 times
...
Junita
11 months ago
I'm a little confused on this one. Is it possible it could be an EMS Cart? I'll have to re-read the question closely.
upvoted 0 times
...
Jacquelyne
11 months ago
I'm a bit unsure about this one. The question is asking for the different types of NIACAP accreditation, but I'm not entirely confident I know what all the options are. I'll have to make an educated guess.
upvoted 0 times
...

Save Cancel