Executives at a company are concerned about employees accessing systems and information about sensitive company projects unrelated to the employees’ normal job duties. Which of the following enterprise security capabilities will the security team most likely deploy to detect that activity?
Choose an answer
Tap an option to check your answer.
Correct answer: UBA.
Why this is the answer
User Behavior Analytics (UBA) is the most suitable capability because it focuses on identifying anomalous or suspicious user activities by establishing baselines of normal behavior. In this scenario, accessing sensitive project information unrelated to an employee's job duties would deviate from their established baseline, triggering an alert. Endpoint Detection and Response (EDR) primarily focuses on detecting and investigating malicious activity on endpoints, not specifically user access patterns to sensitive data. Network Access Control (NAC) manages device access to the network based on security posture, not user activity post-authentication. Data Loss Prevention (DLP) is designed to prevent sensitive data from leaving the organization's control, not necessarily to detect unauthorized internal access to it.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed