Q: 4
[Introduction to Incident Handling and Response]
An insider threat response plan helps an organization minimize the damage caused by malicious
insiders. One of the approaches to mitigate these threats is setting up controls from the human
resources department. Which of the following guidelines can the human resources department use?
Options
Discussion
Option A fits what HR actually does. HR documents and vets access with supervisors as part of onboarding and insider threat prevention. Pretty sure this is what you see in similar exam reports too, not D.
HR doesn't usually run physical security controls, that's more security team's scope. Why would D apply to HR here?
A
A or D? Both make some sense for HR depending on company setup but leaning to A since access vetting is classic HR.
My vote is D for HR involvement, as securing the physical environment is also part of their scope, right?
D
A tbh, HR always docs and vets access with supervisors, classic insider threat mitigation for personnel controls. Don’t see D fitting here.
Its A
A
Be respectful. No spam.