312-50 exam dumps

312-50 practice question 215 of 473

Certified Ethical Hacker (CEH). Associate level, EC-Council. Free question with the correct answer and a full explanation.

312-50 Question 215

Single answer▪ Insider Threats

A company's security team notices that a database administrator who recently submitted a resignation has started querying customer tables outside normal maintenance windows and copying large result sets to a workstation in the finance VLAN. The employee is using valid credentials, and no malware has been detected. As the ethical hacker assisting with an insider-threat assessment, which control would MOST effectively detect and provide evidence of this type of malicious insider activity while minimizing disruption to legitimate administrative access?

  1. A

    Implement database activity monitoring and correlate privileged-user actions with SIEM alerts for anomalous query volume and data exports

  2. B

    Disable all remote administrative access for database administrators until the employee's last working day

  3. C

    Require the employee to change their password immediately and rotate service account credentials weekly

  4. D

    Deploy a perimeter IDS signature to detect outbound SQL traffic from the database server to the internet

Show answer and explanation

Correct answer: A

Explanation

This scenario reflects a classic malicious insider case: a departing employee with legitimate privileged access misusing that access to collect sensitive data. In insider-threat situations, preventive controls are helpful, but detection and evidence collection are critical because the actor often operates with valid credentials and within allowed systems. The best answer is database activity monitoring combined with SIEM correlation, because it captures privileged queries, export behavior, access times, and abnormal usage patterns in a way that supports both rapid response and forensic review.

This aligns with common best practices from NIST guidance on insider threat and logging, including the principle of monitoring privileged-user activity, centralizing log analysis, and detecting anomalous access to sensitive data. It also matches practical enterprise controls such as DAM, UEBA, DLP, and SIEM correlation for high-risk users, especially during triggering events like resignation or termination notice. The other options either focus too narrowly on prevention, are operationally disruptive, or monitor the wrong part of the environment for this type of insider abuse.

  • A. Correct.

    Correct. Database Activity Monitoring (DAM), especially when integrated with a SIEM and user-behavior analytics, is a strong control for insider-threat detection because it records what a privileged user actually does inside the database. In this scenario, the user has valid credentials and is abusing authorized access, so the key need is visibility, anomaly detection, and evidence collection. Monitoring query timing, data volume, table access patterns, and export behavior provides actionable indicators without unnecessarily blocking legitimate DBA functions.

  • B. Incorrect.

    Incorrect. Temporarily disabling all remote administrative access is a broad operational restriction, not the most effective detection control. It may reduce opportunity, but it does not specifically detect or preserve evidence of malicious insider behavior. It also risks disrupting normal operations for other administrators. The question asks for the control that most effectively detects and documents the activity while minimizing disruption.

  • C. Incorrect.

    Incorrect. Changing the employee's password and rotating service account credentials are access-management measures, but they do not address the fact that the insider is currently using legitimate, authorized access. If the organization still intends the DBA to perform duties during the notice period, this step alone does not help identify suspicious database queries, unusual exports, or policy violations. It is more of a containment or hygiene step than a targeted detection mechanism.

  • D. Incorrect.

    Incorrect. A perimeter IDS focused on outbound SQL traffic to the internet is poorly matched to the scenario. The suspicious activity involves internal database queries and copying data to another internal workstation on the finance VLAN, not necessarily SQL traffic leaving the perimeter. Insider threats often operate within trusted internal zones, so network-perimeter monitoring alone may miss the abuse or lack the application-layer context needed to attribute the actions to a privileged insider.

Timed practice exam

Take a 312-50 practice test under exam conditions

125 questions in 240 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam