Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CCOA Exam - Topic 5 Question 22 Discussion

A bank employee is found to be exfiltration sensitive information by uploading it via email. Which of the following security measures would be MOST effective in detecting this type of insider threat?
A) Data loss prevention (DIP)
B) Intrusion detection system (IDS)
C) Network segmentation
D) Security information and event management (SIEM)

Isaca CCOA Exam - Topic 5 Question 22 Discussion

Actual exam question for Isaca's CCOA exam
Question #: 22
Topic #: 5
[All CCOA Questions]

A bank employee is found to be exfiltration sensitive information by uploading it via email. Which of the following security measures would be MOST effective in detecting this type of insider threat?

Show Suggested Answer Hide Answer
Suggested Answer: A

Data Loss Prevention (DLP) systems are specifically designed to detect and prevent unauthorized data transfers. In the context of an insider threat, where a bank employee attempts to exfiltrate sensitive information via email, DLP solutions are most effective because they:

Monitor Data in Motion: DLP can inspect outgoing emails for sensitive content based on pre-defined rules and policies.

Content Inspection and Filtering: It examines email attachments and the body of the message for patterns that match sensitive data (like financial records or PII).

Real-Time Alerts: Generates alerts or blocks the transfer when sensitive data is detected.

Granular Policies: Allows customization to restrict specific types of data transfers, including via email.

Other options analysis:

B . Intrusion detection system (IDS): IDS monitors network traffic for signs of compromise but is not designed to inspect email content or detect data exfiltration specifically.

C . Network segmentation: Reduces the risk of lateral movement but does not directly monitor or prevent data exfiltration through email.

D . Security information and event management (SIEM): SIEM can correlate events and detect anomalies but lacks the real-time data inspection that DLP offers.

CCOA Official Review Manual, 1st Edition Reference:

Chapter 5: Insider Threats and Mitigation: Discusses how DLP tools are essential for detecting data exfiltration.

Chapter 6: Threat Intelligence and Analysis: Covers data loss scenarios and the role of DLP.

Chapter 8: Incident Detection and Response: Explains the use of DLP for detecting insider threats.


Contribute your Thoughts:

0/2000 characters
Allene
2 hours ago
I’m leaning towards DLP too, but I wonder if an IDS could also play a role in identifying unusual email activity.
upvoted 0 times
...
Jessenia
5 days ago
I practiced a similar question, and I feel like network segmentation might not be as effective for detecting insider threats compared to DLP.
upvoted 0 times
...
Barney
10 days ago
I'm not entirely sure, but I remember something about SIEM being useful for monitoring and analyzing security events. Maybe it could help detect this kind of behavior?
upvoted 0 times
...
Vernice
16 days ago
I think data loss prevention (DLP) is the best choice here since it's specifically designed to prevent sensitive data from being leaked.
upvoted 0 times
...

Save Cancel