How to detect employees accessing unrelated sensitive data?

Executives at a company are concerned about employees accessing systems and information about sensitive company projects unrelated to the employees’ normal job duties. Which of the following enterprise security capabilities will the security team most likely deploy to detect that activity?

  1. UBA Source Reference Answer
  2. EDR
  3. NAC
  4. DLP

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the ability to distinguish between behavioral analysis tools and endpoint or network controls, with the trap being confusing UBA with DLP or EDR.

User Behavior Analytics (UBA) is the primary enterprise security capability used to detect anomalies such as employees accessing data outside their job scope. The community consensus confirms UBA is the correct choice over EDR, NAC, or DLP for this specific behavioral monitoring scenario.

Users might select DLP (Data Loss Prevention) because the scenario involves "sensitive information," but DLP focuses on preventing data exfiltration rather than detecting internal access behavior.

Community Discussion (3 comments)

9149f41 👍 1 Selected: A
This case is just for general detection behavior. If an incident already happened, then EDR. So it is A.
Fourgehan 👍 3 Selected: A
User Behavior Analytics (UBA) focuses on monitoring and analyzing user behaviors to detect anomalies, such as accessing systems or information outside of an employee's normal job duties. UBA uses machine learning and behavioral patterns to identify unusual or potentially malicious activities, such as accessing sensitive data unrelated to job roles. This makes it the most appropriate tool for the scenario described.
s_plus 👍 2
*User Behavior Analystics Endpoint Detection & Response Network Access Control Data Loss Prevention

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

User Behavior Analytics (UBA) establishes a baseline of normal user activity and detects deviations from this baseline. When an employee accesses systems or information unrelated to their job duties, it creates a behavioral anomaly that UBA is specifically designed to flag. This makes it the ideal tool for addressing the executives' concerns regarding internal misuse of access privileges.

Why the Other Options Are Wrong

EDR (Endpoint Detection and Response) focuses on identifying threats like malware on devices rather than analyzing user intent or access patterns. NAC (Network Access Control) is concerned with authenticating users and controlling device entry to the network, not monitoring what they do once connected. DLP (Data Loss Prevention) is designed to stop sensitive data from leaving the organization, not necessarily to detect if an employee is simply viewing unauthorized data internally.

Community Comment Notes

Comment [1] accurately highlights that UBA utilizes machine learning to identify unusual activities, which is the core requirement of the scenario. Comment [3] provides a helpful distinction, noting that EDR is typically used for incident response, whereas this scenario describes general behavioral detection.

Official Reference

Exam Strategy

Look for keywords like "baseline," "anomaly," or "normal behavior" to identify UBA questions. Remember that DLP is about data leaving, while UBA is about user actions within the network.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide