FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A risk manager is reviewing the bank's exposure to a malicious insider, such as a database administrator with privileged access. Compared with an external attacker, which characteristic most increases the potential impact of the insider threat?
The key amplifier is that insiders already hold legitimate access and know where sensitive data sits and how controls work. They need not defeat perimeter defenses, and their activity resembles normal use, making detection harder and potential damage larger than for a typical external attacker.
- AInsiders must first defeat perimeter controls such as firewalls
- BInsiders typically leave more forensic evidence than external attackers
- CInsiders already hold legitimate access and knowledge of controls and data locationsCorrect
- DInsiders are generally unable to cause data destruction because of change management
Explanation
Insiders begin with authorized credentials and understand systems, data and control weaknesses, so they can bypass perimeter defenses and avoid detection. Perimeter defeat is an external attacker's hurdle, not an insider's. Their actions look like normal activity, so evidence is harder, not easier, to distinguish, and privileged users can destroy data.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A bank's security team discovers that a critical vulnerability patch was released by the software vendor four months ago but was never appli…
- A bank's staff receive emails appearing to come from the CEO, urging an urgent wire transfer to a new supplier account and asking for secrec…
- A firm estimates that a data breach has a 10% annual probability. If it occurs, the loss is USD 20 million with probability 0.7 and USD 60 m…
- A regional bank's risk committee wants a control framework that arranges cyber controls in sequence so that the failure of one control does …
- A bank's risk team wants to express cyber risk in financial terms for the board. Which approach best reflects a quantitative cyber risk meas…
- Following a ransomware incident, a firm finds its backups were stored on the same network and were encrypted along with production data. Whi…