mediumMultiple SelectObjective-mapped
CS0-003 Practice Question: A security analyst suspects an insider threat…
A security analyst suspects an insider threat based on unusual data access patterns by an employee. According to best practices, which TWO actions should the analyst take FIRST?
⚠ Common exam trap
CompTIA often tests the distinction between 'immediate containment' and 'overreaction' — the trap here is that candidates confuse 'suspending accounts' (a disruptive, all-or-nothing action) with 'restricting access' (a precise, reversible control), leading them to choose B instead of A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict the employee's access to sensitive data.
Restricting the employee's access to sensitive data (A) is a correct first action because it immediately reduces the risk of further data exfiltration or damage while preserving the ability to investigate. Collecting additional evidence without alerting the employee (D) is also correct because it allows the analyst to build a forensic case covertly, preventing the insider from destroying evidence or altering behavior. Both actions align with the incident response principle of containment before eradication and the need to avoid tipping off a potential adversary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Restrict the employee's access to sensitive data.
Why this is correct
Restricting an employee's access to sensitive data is a critical, immediate containment measure during an insider threat investigation. This action adheres to the principle of least privilege, mitigating potential data exfiltration or damage without prematurely alerting the suspect. It allows the security team to safely conduct further investigation and evidence collection while minimizing ongoing risk to organizational assets.
- ✗
Suspend the employee's accounts outright.
Why it's wrong here
Suspending an employee's accounts outright is an overly aggressive and premature action based solely on suspicion. Such a drastic step could immediately alert the suspected insider, potentially leading to the destruction of evidence or further malicious actions from alternative vectors. Furthermore, it carries significant human resources implications if the initial suspicion proves unfounded, causing unnecessary organizational disruption.
- ✗
Immediately notify law enforcement.
Why it's wrong here
Immediately notifying law enforcement is premature when an insider threat is only suspected and not yet confirmed through a thorough internal investigation. Law enforcement involvement is typically reserved for confirmed criminal activity or severe data breaches after internal evidence collection and analysis. Premature notification can complicate internal incident response processes, potentially hinder the investigation, and unnecessarily strain organizational resources.
- ✓
Collect additional evidence without alerting the employee.
Why this is correct
Collecting additional evidence without alerting the employee is a fundamental and crucial step in the investigation phase of incident response. This covert approach allows the security team to gather comprehensive forensic data, such as system logs, network traffic, and endpoint telemetry, to confirm the suspicion and build a robust case. Alerting the employee prematurely could lead to evidence tampering, destruction, or further malicious actions, compromising the integrity of the entire investigation.
- ✗
Confront the employee about the behavior.
Why it's wrong here
Confronting the employee about their behavior at this early stage of suspicion is highly inadvisable and counterproductive to an effective investigation. Direct engagement could immediately alert the suspected insider, prompting them to destroy critical digital evidence, escalate their malicious activities, or even retaliate against the organization. Incident response best practices dictate covert evidence collection and confirmation before any direct interaction with the subject.
Go deeper
Related to this question
Learn chapter
Threat Intelligence and Threat Hunting
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Eradication
Eradication is the phase in incident response where the root cause of a security breach is completely removed from the system to prevent the attack from happening again.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.