Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A security manager is assessing the risk of insider threat for a healthcare organization. Which of the following is the most appropriate way to categorize a malicious insider who intentionally exfiltrates patient data?

⚠ Common exam trap

The trap here is focusing on the technical method of exfiltration and misclassifying the threat source as technical, when the actor is human.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Human threat

Threat sources are commonly categorized as natural, human, and environmental. A malicious insider who intentionally exfiltrates data is a human threat because the act is deliberate and performed by a person. This classification directs risk managers to apply controls such as background checks, least privilege, separation of duties, and continuous monitoring, which are effective against human threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Natural threat

    Why it's wrong here

    Natural threats include events such as floods, earthquakes, and pandemics. A malicious insider is a human actor who intentionally causes harm, not a natural event. Categorizing this as a natural threat would misrepresent the source and lead to inappropriate risk treatment, such as focusing on business continuity rather than access controls and monitoring.

  • ✗

    Technical threat

    Why it's wrong here

    Technical threats typically refer to failures or weaknesses in systems, such as software bugs or hardware malfunctions. While a malicious insider may use technical means to exfiltrate data, the threat source is the person, not the technology. The scenario describes intentional human action, so labeling it a technical threat misidentifies the root cause and could lead to misplaced controls.

  • ✓

    Human threat

    Why this is correct

    A malicious insider is a human threat source because the action is deliberate and carried out by a person. Human threats can be internal or external, and they include both intentional and unintentional acts. In this scenario, the insider intentionally exfiltrates data, which clearly falls under the human threat category, making this the correct classification.

  • ✗

    Environmental threat

    Why it's wrong here

    Environmental threats relate to conditions such as power failures, humidity, or temperature extremes that affect physical assets. A malicious insider is not an environmental condition but a person acting with intent. Classifying this as an environmental threat would ignore the human motivation and the need for controls like least privilege and user behavior analytics.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.