How to detect employees accessing unrelated sensitive data?
Executives at a company are concerned about employees accessing systems and information about sensitive company projects unrelated to the employees’ normal job duties. Which of the following enterprise security capabilities will the security team most likely deploy to detect that activity?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the ability to distinguish between behavioral analysis tools and endpoint or network controls, with the trap being confusing UBA with DLP or EDR.
User Behavior Analytics (UBA) is the primary enterprise security capability used to detect anomalies such as employees accessing data outside their job scope. The community consensus confirms UBA is the correct choice over EDR, NAC, or DLP for this specific behavioral monitoring scenario.
Users might select DLP (Data Loss Prevention) because the scenario involves "sensitive information," but DLP focuses on preventing data exfiltration rather than detecting internal access behavior.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
User Behavior Analytics (UBA) establishes a baseline of normal user activity and detects deviations from this baseline. When an employee accesses systems or information unrelated to their job duties, it creates a behavioral anomaly that UBA is specifically designed to flag. This makes it the ideal tool for addressing the executives' concerns regarding internal misuse of access privileges.Why the Other Options Are Wrong
EDR (Endpoint Detection and Response) focuses on identifying threats like malware on devices rather than analyzing user intent or access patterns. NAC (Network Access Control) is concerned with authenticating users and controlling device entry to the network, not monitoring what they do once connected. DLP (Data Loss Prevention) is designed to stop sensitive data from leaving the organization, not necessarily to detect if an employee is simply viewing unauthorized data internally.Community Comment Notes
Comment [1] accurately highlights that UBA utilizes machine learning to identify unusual activities, which is the core requirement of the scenario. Comment [3] provides a helpful distinction, noting that EDR is typically used for incident response, whereas this scenario describes general behavioral detection.Official Reference
Exam Strategy
Look for keywords like "baseline," "anomaly," or "normal behavior" to identify UBA questions. Remember that DLP is about data leaving, while UBA is about user actions within the network.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →