For the insider threat question, the prompt says the insider has legitimate access, therefore, implying the insider is misusing their access. I don't understand how enforcing strict password policies or implementing RBAC would help given that the insider has legitimate access. The question could be worded differently to support those two actions IMHO. I have my sec+ 701 exam soon and your PBQ videos are very helpful!
@jrsimeon022 ай бұрын
I suppose the question interprets legitimate access and authorized access as different.
@96vintxge6 ай бұрын
For the second question, why would you not encrypt data immediately? Wouldn't that help with future data breaches?
@tylermisyak64455 ай бұрын
Preventing future data breaches is part of the Post Incident Activity Phase, which is the last phase in the IRC, so encrypting data would not be done immediately.