Exam CISM All QuestionsBrowse all questions from this exam
Question 502

Which of the following is the BEST way to prevent insider threats?

    Correct Answer: C

    The best way to prevent insider threats is to enforce segregation of duties and least privilege access. By ensuring that employees only have access to the systems and data necessary for their job functions, organizations can minimize the risk of misuse or abuse of sensitive information. This approach limits the potential damage that an insider can cause, as they do not possess unnecessary access privileges.

Discussion
CarlLimpsOption: C

C. the key word here is "prevent" which is what SOD and least privilege does. Logging is used for detective control.

ManzerOption: C

The key is prevent. Logs do not prevent.

SIMTEINOption: C

C. the key word here is "prevent" which is what SOD and least privilege does. Logging is used for detective control

ZiggyboobooOption: C

C for me

richck102Option: C

C. Enforce segregation of duties and least privilege access.

richck102

or B. Conduct organization-wide security awareness training. ........why not

AaronS1990

Because you'd also be training the insider threat who doesn't care at all for the training. Minimizing their access however would impede them.

Uncle_Lucifer

But not prevent the attack nonetheless. The choices are crappy, but B is still best for preventing. C is best answer for mitigating

DravidianOption: C

Yea, D is clearly the most incorrect answer here. The question is asking about preventing. Logging is a detective control and has provides no value to the question.

Souvik124Option: C

Preventing insider threats can be challenging as they are often caused by individuals with legitimate access to an organization's systems and data. However, implementing a combination of preventative measures can help mitigate the risk. Of the options listed, the BEST way to prevent insider threats is to enforce segregation of duties and least privilege access (Option C).

aokisanOption: C

Clearly, C.

afb4b17Option: D

Answer C will reduce the impact of insider attack. Logging in itself is not enough. The answer should be " logging with monitoring of anomalies.

Uncle_LuciferOption: B

some people are saying least privilege and roles can prevent insider attack, it wont. it will limit the impact due to limitation. best answer is user training. --> B

xcjxcj

Training is good for outside threat.

xcjxcj

A trainned insider is more dangerous

oluchecpointOption: C

C. Enforce segregation of duties and least privilege access. Enforcing segregation of duties and implementing the principle of least privilege access means that employees are only granted access to the systems, data, and resources they need to perform their specific job functions. This reduces the risk of employees having unnecessary access to sensitive information and limits their ability to misuse or abuse their privileges.

karanvp

This question talk about Threat; but not incident/risk. Even with least priority, the internal people still can be a threat to organization and it's assets(including physical threat); if there is no proper log, then can't find difficult to identify the threat too. If internal people knows who will be caught through logs, then he/she won't do any vulnerable activities.

karanvp

Correction ".....can't find difficult to identify the person who is threat for the organisation......."

welloOption: C

C. Enforce segregation of duties and least privilege access.