Which Scenario Describes Departments Bypassing Corporate VPN?
A systems administrator notices that the research and development department is not using the company VPN when accessing various company-related services and systems. Which of the following scenarios describes this activity?
Community Votes
85% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the ability to distinguish between procedural control violations and actual malicious incidents, with the trap being premature assumptions of data theft or espionage without evidence.
This question identifies Shadow IT, where employees bypass official IT controls like VPNs to access corporate resources. The community strongly supports option D, emphasizing that unapproved technology usage represents a governance and operational risk rather than an active threat.
Candidates frequently select Data Exfiltration (B) because bypassing a VPN often signals a security breach; however, the scenario lacks any evidence of unauthorized data transfer, making it a policy violation rather than a theft event.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Shadow IT Adoption
The scenario directly describes Shadow IT, which refers to hardware, software, or network services procured and utilized by employees without explicit approval from the organization’s IT or security teams. In this case, the Research and Development department is circumventing the mandated corporate VPN to access internal resources. While their intention may be productivity or convenience, bypassing approved security channels creates unmanaged exposure, violates compliance policies, and introduces unvetted vulnerabilities into the enterprise environment.Why the Other Options Are Incorrect
- Espionage (A) implies deliberate, covert intelligence gathering, typically by insiders or external actors stealing trade secrets. There is absolutely no indication of malicious intent or secret surveillance in the prompt.
- Data Exfiltration (B) requires concrete evidence of unauthorized data movement outside the organization. As multiple community members noted, merely skipping a VPN does not automatically mean data is being stolen; it is a control violation, not necessarily a theft event.
- Nation-State Attack (C) involves highly sophisticated, state-sponsored campaigns targeting critical infrastructure or government entities. This scenario lacks the funding, specialized tools, and strategic objectives characteristic of such advanced persistent threats.
Expert Takeaway & Community Validation
The CompTIA exam heavily penalizes assumption-based answers. Test-takers must strictly adhere to the facts presented: the prompt highlights a process and control bypass, not an active threat or data loss event. The overwhelming community consensus (85% voting D) aligns with official study materials, which classify unsanctioned resource access as a governance and operational risk rather than an immediate incident response scenario.Official Reference
Exam Strategy
Always anchor your answer strictly to the facts presented in the scenario; never assume malicious intent or data loss unless explicitly stated. When employees bypass IT protocols for convenience, prioritize risk management and governance concepts like Shadow IT over incident response or threat actor classifications.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →