CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 502


Which of the following is the BEST way to prevent insider threats?

Show Answer
Correct Answer: CD

The best way to prevent insider threats is to enforce segregation of duties and least privilege access. By ensuring that employees only have access to the systems and data necessary for their job functions, organizations can minimize the risk of misuse or abuse of sensitive information. This approach limits the potential damage that an insider can cause, as they do not possess unnecessary access privileges.

Discussion

13 comments
Sign in to comment
CarlLimpsOption: C
Feb 19, 2023

C. the key word here is "prevent" which is what SOD and least privilege does. Logging is used for detective control.

ManzerOption: C
Dec 18, 2022

The key is prevent. Logs do not prevent.

ZiggyboobooOption: C
Dec 16, 2022

C for me

SIMTEINOption: C
Feb 26, 2023

C. the key word here is "prevent" which is what SOD and least privilege does. Logging is used for detective control

aokisanOption: C
Dec 21, 2022

Clearly, C.

Souvik124Option: C
Feb 17, 2023

Preventing insider threats can be challenging as they are often caused by individuals with legitimate access to an organization's systems and data. However, implementing a combination of preventative measures can help mitigate the risk. Of the options listed, the BEST way to prevent insider threats is to enforce segregation of duties and least privilege access (Option C).

DravidianOption: C
May 6, 2023

Yea, D is clearly the most incorrect answer here. The question is asking about preventing. Logging is a detective control and has provides no value to the question.

richck102Option: C
Jun 28, 2023

C. Enforce segregation of duties and least privilege access.

richck102
Jun 28, 2023

or B. Conduct organization-wide security awareness training. ........why not

AaronS1990
Aug 26, 2023

Because you'd also be training the insider threat who doesn't care at all for the training. Minimizing their access however would impede them.

Uncle_Lucifer
Dec 9, 2023

But not prevent the attack nonetheless. The choices are crappy, but B is still best for preventing. C is best answer for mitigating

welloOption: C
Jun 11, 2023

C. Enforce segregation of duties and least privilege access.

karanvp
Jun 24, 2023

This question talk about Threat; but not incident/risk. Even with least priority, the internal people still can be a threat to organization and it's assets(including physical threat); if there is no proper log, then can't find difficult to identify the threat too. If internal people knows who will be caught through logs, then he/she won't do any vulnerable activities.

karanvp
Jun 24, 2023

Correction ".....can't find difficult to identify the person who is threat for the organisation......."

oluchecpointOption: C
Sep 7, 2023

C. Enforce segregation of duties and least privilege access. Enforcing segregation of duties and implementing the principle of least privilege access means that employees are only granted access to the systems, data, and resources they need to perform their specific job functions. This reduces the risk of employees having unnecessary access to sensitive information and limits their ability to misuse or abuse their privileges.

Uncle_LuciferOption: B
Dec 9, 2023

some people are saying least privilege and roles can prevent insider attack, it wont. it will limit the impact due to limitation. best answer is user training. --> B

xcjxcj
Feb 22, 2024

Training is good for outside threat.

xcjxcj
Feb 22, 2024

A trainned insider is more dangerous

afb4b17Option: D
Jun 16, 2024

Answer C will reduce the impact of insider attack. Logging in itself is not enough. The answer should be " logging with monitoring of anomalies.