Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

An organization wants to detect insider threats by identifying abnormal user behavior. Which technology is best suited for this purpose?

⚠ Common exam trap

A common mistake is to choose Network-based IDS, but insider threats often involve legitimate credentials and non-malicious traffic, so a solution focused on user behavior (UBA) is required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User Behavior Analytics (UBA)

User Behavior Analytics (UBA) is specifically designed to detect insider threats by establishing a baseline of normal user activity and then identifying anomalous deviations, such as unusual login times, abnormal data access patterns, or atypical file transfers. Unlike other security tools that rely on known signatures or network traffic patterns, UBA applies machine learning and statistical modeling to user-centric data (e.g., authentication logs, file system events, and endpoint activity) to uncover subtle, non-signature-based indicators of malicious insider behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    User Behavior Analytics (UBA)

    Why this is correct

    UBA baselines each user's normal activity, then flags statistically significant deviations such as unusual access times, volumes or data transfers. This satisfies the requirement to identify abnormal user behaviour indicative of insider threat, which signature-based tools cannot detect.

  • ✗

    Network-based IDS

    Why it's wrong here

    Network-based IDS inspects packet flows for known attack signatures and protocol anomalies, giving no visibility into user account behaviour or data-access patterns. Insider detection needs user behaviour analytics correlating identity, access and activity. A network IDS would be correct for detecting malicious traffic crossing the perimeter.

  • ✗

    Vulnerability scanner

    Why it's wrong here

    A vulnerability scanner enumerates known software flaws and missing patches on hosts and applications; it does not model individual user behaviour. Insider threat detection depends on behavioural analytics over identity and access events. Vulnerability scanning would be correct for prioritising remediation of technical weaknesses.

  • ✗

    Signature-based antivirus

    Why it's wrong here

    Signature-based antivirus matches known file hashes and patterns, so it cannot flag novel or legitimate-but-unusual user activity. Insider threat detection requires behavioural baselining and anomaly analytics. Signature matching would be correct for blocking known malware, not for identifying deviations in user conduct.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.