Courseiva
hardMultiple Choice

Insider Threat Investigation: Why Administrative Privileges Are the Primary Challenge

You are a security analyst investigating a potential insider threat incident. An employee from the finance department has been behaving suspiciously: printing large volumes of sensitive financial reports, accessing files outside their normal work hours, and attempting to bypass the company's data loss prevention (DLP) controls by renaming files before emailing them. The employee has been with the company for 10 years and has a clean record. The company's policy requires that any investigation be conducted discreetly to avoid alerting the employee. You need to gather evidence to confirm or refute the suspicion. Which of the following actions should you take FIRST?

⚠ Common exam trap

ISC2 often tests the principle that investigative actions must be non-disruptive and evidence-driven first, tempting candidates to jump to containment (Option C) or escalation (Option D) before analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the employee's system logs and DLP alerts in detail to establish a pattern.

The first step in any insider threat investigation is to gather and analyze available evidence discreetly, as required by policy. Reviewing system logs (e.g., Windows Event Logs, file server audit logs) and DLP alerts allows you to establish a behavioral pattern—such as anomalous access times, file rename operations, and email attachments—without alerting the employee. This evidence-based approach ensures you can confirm or refute the suspicion before taking any disruptive or confrontational actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Confront the employee directly to ask for an explanation.

    Why it's wrong here

    Confronting the employee alerts the subject, letting them destroy evidence and defeating the discreet-investigation requirement. It is tempting because seeking an explanation appears cooperative, but that approach belongs after evidence gathering, not as the first investigative step.

  • ✓

    Review the employee's system logs and DLP alerts in detail to establish a pattern.

    Why this is correct

    Logs and DLP alerts are already generated, so reviewing them is passive, discreet and non-disruptive, establishing a pattern without alerting the employee. This satisfies the policy constraint requiring the investigation remain covert while evidence is gathered.

  • ✗

    Disable the employee's network access immediately to prevent data exfiltration.

    Why it's wrong here

    Disabling network access immediately tips off the employee and halts ongoing evidence collection, breaching the discreet-investigation requirement. It is tempting because containment limits exfiltration, yet that action belongs once evidence confirms the threat, not as the first step.

  • ✗

    Notify the employee's manager about the suspicion.

    Why it's wrong here

    Notifying the manager breaches the requirement for a discreet investigation, since the manager could inadvertently alert the employee and compromise evidence gathering. It is tempting because managers normally receive insider-threat reports, and this would be correct once covert evidence collection and HR or legal coordination are already complete.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.