220-1102 exam dumps

220-1102 practice question 449 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 449

Single answerInsider threat

A help desk technician notices that a payroll employee has been copying large amounts of salary data to a personal cloud storage account during late evening hours. The employee is authorized to view payroll records as part of their job, but storing that data in a personal account violates company policy. Which of the following best describes this security risk?

  1. A

    Insider threat

  2. B

    Whaling attack

  3. C

    Zero-day exploit

  4. D

    Distributed denial-of-service (DDoS) attack

Show answer and explanation

Correct answer: A

Explanation

This scenario is an example of an insider threat because the risk comes from a trusted individual who already has legitimate access to sensitive information. On the CompTIA A+ Core 2 exam, candidates should recognize that insider threats are not limited to malicious attackers; they can also involve careless or policy-violating behavior by employees with valid access. In real environments, best practices include enforcing data handling policies, monitoring for unusual file transfers, applying least privilege, using data loss prevention (DLP) controls where available, and escalating suspicious activity according to company incident response procedures. Guidance from sources such as NIST emphasizes monitoring, access control, and user awareness as key methods for reducing insider risk.

  • A. Correct.

    Correct. An insider threat involves a current or former employee, contractor, or other trusted person who misuses legitimate access in a way that creates a security risk. In this scenario, the employee has authorized access to payroll data but is handling it improperly by copying it to a personal cloud account, which is a classic insider threat situation.

  • B. Incorrect.

    Incorrect. A whaling attack is a type of phishing attack that targets high-profile individuals such as executives. The scenario does not involve deceptive emails or credential theft; it involves misuse of authorized access by an internal user.

  • C. Incorrect.

    Incorrect. A zero-day exploit refers to an attack that takes advantage of a previously unknown or unpatched software vulnerability. Nothing in the scenario indicates exploitation of a software flaw. The issue is inappropriate data handling by an authorized employee.

  • D. Incorrect.

    Incorrect. A DDoS attack attempts to overwhelm a service or network with traffic to make it unavailable. The scenario involves potential data exfiltration by an employee, not service disruption caused by external traffic.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam