SY0-701 exam dumps

SY0-701 practice question 482 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 482

Single answerAnomalous behavior recognition: Risky , Unexpected , Unintentional

A security analyst is reviewing activity in a company's SaaS environment after a data loss prevention alert. The analyst finds that a marketing employee exported a large customer contact list to a personal cloud storage account at 2:00 a.m. The employee used valid credentials, there is no evidence of malware, and the employee later says they were trying to finish a presentation from home because the approved file-sharing platform was too slow. Which anomalous behavior category best describes this activity?

  1. A

    Risky behavior

  2. B

    Unexpected behavior

  3. C

    Unintentional behavior

  4. D

    Normal behavior

Show answer and explanation

Correct answer: A

Explanation

The best answer is risky behavior. In anomalous behavior recognition, analysts often distinguish between risky, unexpected, and unintentional actions. Risky behavior involves a user knowingly taking unsafe shortcuts or bypassing policy, even without malicious intent. Unexpected behavior focuses more on deviations from an established baseline, and unintentional behavior refers to accidents or mistakes. In this scenario, the employee deliberately used valid access in an unsafe way by moving sensitive data to a personal service. That aligns most closely with risky behavior. This approach is consistent with common security operations and insider risk practices, as well as guidance from NIST on monitoring for policy violations, data exfiltration indicators, and misuse of authorized access.

  • A. Correct.

    Correct. This is best classified as risky behavior because the employee knowingly bypassed approved processes and transferred sensitive business data to a personal cloud account, creating security and compliance exposure. The action may not have been malicious, but it introduced significant risk through unsafe decision-making.

  • B. Incorrect.

    Incorrect. Unexpected behavior usually refers to activity that deviates from a user's normal baseline, such as unusual login times, impossible travel, or atypical system access patterns. While the 2:00 a.m. timing is unusual, the stronger classification in this scenario is that the user deliberately chose an unsafe method to handle sensitive data.

  • C. Incorrect.

    Incorrect. Unintentional behavior typically involves accidental actions, such as sending data to the wrong recipient, misconfiguring permissions, or clicking a phishing link without realizing the consequences. In this case, the employee intentionally exported the data and intentionally used a personal cloud account, even if the user did not intend harm.

  • D. Incorrect.

    Incorrect. Exporting sensitive customer data to a personal cloud storage service is not normal behavior in a controlled enterprise environment. Even if the employee had a business reason, this would still be considered anomalous and a policy violation in most organizations.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam