Courseiva
mediumMultiple SelectObjective-mapped

CS0-003 Practice Question: A security analyst suspects an insider threat…

A security analyst suspects an insider threat based on unusual data access patterns by an employee. According to best practices, which TWO actions should the analyst take FIRST?

⚠ Common exam trap

CompTIA often tests the distinction between 'immediate containment' and 'overreaction' — the trap here is that candidates confuse 'suspending accounts' (a disruptive, all-or-nothing action) with 'restricting access' (a precise, reversible control), leading them to choose B instead of A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Restrict the employee's access to sensitive data.

Restricting the employee's access to sensitive data (A) is a correct first action because it immediately reduces the risk of further data exfiltration or damage while preserving the ability to investigate. Collecting additional evidence without alerting the employee (D) is also correct because it allows the analyst to build a forensic case covertly, preventing the insider from destroying evidence or altering behavior. Both actions align with the incident response principle of containment before eradication and the need to avoid tipping off a potential adversary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Restrict the employee's access to sensitive data.

    Why this is correct

    Restricting an employee's access to sensitive data is a critical, immediate containment measure during an insider threat investigation. This action adheres to the principle of least privilege, mitigating potential data exfiltration or damage without prematurely alerting the suspect. It allows the security team to safely conduct further investigation and evidence collection while minimizing ongoing risk to organizational assets.

  • Suspend the employee's accounts outright.

    Why it's wrong here

    Suspending an employee's accounts outright is an overly aggressive and premature action based solely on suspicion. Such a drastic step could immediately alert the suspected insider, potentially leading to the destruction of evidence or further malicious actions from alternative vectors. Furthermore, it carries significant human resources implications if the initial suspicion proves unfounded, causing unnecessary organizational disruption.

  • Immediately notify law enforcement.

    Why it's wrong here

    Immediately notifying law enforcement is premature when an insider threat is only suspected and not yet confirmed through a thorough internal investigation. Law enforcement involvement is typically reserved for confirmed criminal activity or severe data breaches after internal evidence collection and analysis. Premature notification can complicate internal incident response processes, potentially hinder the investigation, and unnecessarily strain organizational resources.

  • Collect additional evidence without alerting the employee.

    Why this is correct

    Collecting additional evidence without alerting the employee is a fundamental and crucial step in the investigation phase of incident response. This covert approach allows the security team to gather comprehensive forensic data, such as system logs, network traffic, and endpoint telemetry, to confirm the suspicion and build a robust case. Alerting the employee prematurely could lead to evidence tampering, destruction, or further malicious actions, compromising the integrity of the entire investigation.

  • Confront the employee about the behavior.

    Why it's wrong here

    Confronting the employee about their behavior at this early stage of suspicion is highly inadvisable and counterproductive to an effective investigation. Direct engagement could immediately alert the suspected insider, prompting them to destroy critical digital evidence, escalate their malicious activities, or even retaliate against the organization. Incident response best practices dictate covert evidence collection and confirmation before any direct interaction with the subject.

About these practice questions

One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.