PSC Personnel Security & Insider Threats 2 — Questions and Answers
Question 1: Which federal framework is commonly referenced when developing insider threat programs for US organizations?
- OSHA 1910
- Executive Order 13587 and the National Insider Threat Policy (Correct answer)
- HIPAA Security Rule
- FEMA IS-100
Correct answer: Executive Order 13587 and the National Insider Threat Policy
Executive Order 13587 and the National Insider Threat Policy established the foundation for insider threat programs across US government and affiliated organizations.
Question 2: A security manager notices an employee is downloading large volumes of data just before their resignation date. This behavior is best described as:
- Normal pre-departure housekeeping
- A potential data exfiltration insider threat indicator (Correct answer)
- A technical error requiring IT support
- An HR matter only
Correct answer: A potential data exfiltration insider threat indicator
Bulk data downloads prior to departure are a recognized behavioral indicator of potential data exfiltration by a departing insider.
Question 3: What is the purpose of a security clearance adjudication process?
- To assign parking spaces based on rank
- To determine whether an individual is eligible for access to classified or sensitive information based on loyalty, reliability, and trustworthiness (Correct answer)
- To evaluate an employee's technical skills
- To establish salary grades for security roles
Correct answer: To determine whether an individual is eligible for access to classified or sensitive information based on loyalty, reliability, and trustworthiness
Adjudication evaluates background investigation results to determine if an individual meets the standards of loyalty, reliability, and trustworthiness required for sensitive access.
Question 4: Which of the following is an example of a technical control used to monitor insider threat activity?
- Employee satisfaction surveys
- User and entity behavior analytics (UEBA) tools (Correct answer)
- Mandatory annual performance reviews
- Open-office floor plans
Correct answer: User and entity behavior analytics (UEBA) tools
UEBA tools analyze patterns in user behavior and flag anomalies that may indicate insider threat activity.
Question 5: What should an organization do when an employee is placed on administrative leave pending an investigation?
- Allow full system access to avoid disrupting workflows
- Immediately revoke or suspend all physical and logical access credentials (Correct answer)
- Notify all customers of the situation
- Continue normal operations without any changes
Correct answer: Immediately revoke or suspend all physical and logical access credentials
Revoking access upon administrative leave prevents the subject of an investigation from destroying evidence or causing further harm.
Question 6: Which psychological stressor is commonly associated with increased insider threat risk?
- Receiving a promotion
- Financial hardship combined with perceived workplace grievances (Correct answer)
- Winning a company award
- Being assigned to a new project
Correct answer: Financial hardship combined with perceived workplace grievances
Financial hardship paired with workplace grievances is a well-documented combination that elevates an individual's risk profile for insider threat behavior.
Which federal framework is commonly referenced when developing insider threat programs for US organizations?