A security analyst is investigating a potential insider threat. Which TWO indicators are most commonly associated with malicious insider activity? (Choose two.)
This is a common indicator of anomalous behavior.
Why this answer
Insider threats often involve unusual access patterns (e.g., accessing sensitive data not needed for the role) and attempts to bypass security controls (e.g., disabling logging).