Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

A risk manager is reviewing the bank's exposure to a malicious insider, such as a database administrator with privileged access. Compared with an external attacker, which characteristic most increases the potential impact of the insider threat?

The key amplifier is that insiders already hold legitimate access and know where sensitive data sits and how controls work. They need not defeat perimeter defenses, and their activity resembles normal use, making detection harder and potential damage larger than for a typical external attacker.

  1. AInsiders must first defeat perimeter controls such as firewalls
  2. BInsiders typically leave more forensic evidence than external attackers
  3. CInsiders already hold legitimate access and knowledge of controls and data locationsCorrect
  4. DInsiders are generally unable to cause data destruction because of change management

Explanation

Insiders begin with authorized credentials and understand systems, data and control weaknesses, so they can bypass perimeter defenses and avoid detection. Perimeter defeat is an external attacker's hurdle, not an insider's. Their actions look like normal activity, so evidence is harder, not easier, to distinguish, and privileged users can destroy data.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions