Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC Exam GCED Topic 3 Question 36 Discussion

Actual exam question for GIAC's GIAC Certified Enterprise Defender exam
Question #: 36
Topic #: 3
[All GIAC Certified Enterprise Defender Questions]

Which statement below is the MOST accurate about insider threat controls?

Show Suggested Answer Hide Answer
Suggested Answer: A

A company needs to classify its information as a key step in valuing it and knowing where to focus its protection.

Rotation of duties and separation of duties are both key elements in reducing the scope of information access and the ability to conceal malicious behavior.

Separation of duties helps minimize ''empire building'' within a company, keeping one individual from controlling a great deal of information, reducing the insider threat.

Security awareness programs can help other employees notice the signs of an insider attack and thus reduce the insider threat.

Detection is a reactive method and only occurs after an attack occurs. Only preventative methods can stop or limit an attack.


Contribute your Thoughts:

Leonora
10 days ago
I'm going with A). It's all about identifying the data that needs to be protected. That's the foundation for effective insider threat controls.
upvoted 0 times
...
Gertude
12 days ago
Haha, E) is a good one. Encouraging one employee to control a great deal of information? That's just asking for trouble. Talk about a recipe for disaster!
upvoted 0 times
...
Lavonna
13 days ago
D)? Seriously? Rotation of duties makes an insider threat more likely? That's just backwards. Separation of duties is where it's at, folks.
upvoted 0 times
...
Dominque
14 days ago
B) is just plain wrong. Security awareness programs are crucial for reducing the insider threat. How else are employees going to know what to look out for?
upvoted 0 times
...
Emelda
16 days ago
Hmm, I'm not so sure. I think C) is the best answer - both detective and preventative controls are important for preventing insider attacks. You need a multi-layered approach, you know?
upvoted 0 times
...
Stevie
17 days ago
Oh, this is a tricky one! I think the MOST accurate statement is A) - classification of information assets helps identify data to protect. That's key for mitigating insider threats, isn't it?
upvoted 0 times
...

Save Cancel