hardMultiple ChoiceObjective-mapped
ISC2 CC Practice Question: A security analyst investigating a potential…
You are a security analyst investigating a potential insider threat incident. An employee from the finance department has been behaving suspiciously: printing large volumes of sensitive financial reports, accessing files outside their normal work hours, and attempting to bypass the company's data loss prevention (DLP) controls by renaming files before emailing them. The employee has been with the company for 10 years and has a clean record. The company's policy requires that any investigation be conducted discreetly to avoid alerting the employee. You need to gather evidence to confirm or refute the suspicion. Which of the following actions should you take FIRST?
⚠ Common exam trap
ISC2 often tests the principle that investigative actions must be non-disruptive and evidence-driven first, tempting candidates to jump to containment (Option C) or escalation (Option D) before analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the employee's system logs and DLP alerts in detail to establish a pattern.
The first step in any insider threat investigation is to gather and analyze available evidence discreetly, as required by policy. Reviewing system logs (e.g., Windows Event Logs, file server audit logs) and DLP alerts allows you to establish a behavioral pattern—such as anomalous access times, file rename operations, and email attachments—without alerting the employee. This evidence-based approach ensures you can confirm or refute the suspicion before taking any disruptive or confrontational actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Confront the employee directly to ask for an explanation.
Why it's wrong here
Confrontation may alert the employee and is not evidence-based.
- ✓
Review the employee's system logs and DLP alerts in detail to establish a pattern.
Why this is correct
Logs provide objective data; this step is non-intrusive and evidence-gathering.
- ✗
Disable the employee's network access immediately to prevent data exfiltration.
Why it's wrong here
Action without evidence may be premature and could disrupt operations.
- ✗
Notify the employee's manager about the suspicion.
Why it's wrong here
The manager may not understand the need for discretion and could alert the employee.
Go deeper
Related to this question
Learn chapter
Introduction to Security Principles
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 976 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.