問題文
A pharmaceutical firm finds that a researcher who resigned last week had, in the preceding month, downloaded far more formulation documents than the role normally requires. Every download used the researcher's own valid credentials and stayed inside permitted folders. Why is this kind of threat harder to detect than an external intrusion?
選択肢
- Because the researcher would have had to defeat the firm's multi-factor authentication in order to reach the formulation folders, and any method capable of defeating that control leaves no trace at all in the authentication records that the firm keeps.
- Because documents that sit inside permitted folders are never written to any access log, so the firm has no record of who opened them and can only find out by asking the people who work in that part of the business.
- Because an insider is able to switch off the monitoring platform before starting, which is why the downloads did not appear on any dashboard while they were happening.
- Because the activity uses legitimate access and produces no failed logins or boundary alerts, so detection has to rest on how the volume and timing differ from the person's own normal pattern.