Which Scenario Describes Departments Bypassing Corporate VPN?

A systems administrator notices that the research and development department is not using the company VPN when accessing various company-related services and systems. Which of the following scenarios describes this activity?

  1. Espionage
  2. Data exfiltration
  3. Nation-state attack
  4. Shadow IT Source Reference Answer

Community Votes

D
85%
B
15%

85% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the ability to distinguish between procedural control violations and actual malicious incidents, with the trap being premature assumptions of data theft or espionage without evidence.

This question identifies Shadow IT, where employees bypass official IT controls like VPNs to access corporate resources. The community strongly supports option D, emphasizing that unapproved technology usage represents a governance and operational risk rather than an active threat.

Candidates frequently select Data Exfiltration (B) because bypassing a VPN often signals a security breach; however, the scenario lacks any evidence of unauthorized data transfer, making it a policy violation rather than a theft event.

Community Discussion (6 comments)

nillie 👍 6 Selected: D
The scenario described is: D. Shadow IT Shadow IT refers to the use of technology, systems, or services by employees without the approval or knowledge of the IT department. In this case, the research and development department is bypassing the company’s VPN, potentially using unauthorized methods to access company-related services and systems. This can pose security risks, as these systems may not adhere to the company’s security policies and protocols.
ITExperts 👍 2 Selected: D
D, espionage given here is crazy lmao
gingergroot 👍 1 Selected: B
B. Data exfiltration From the official CompTIA SYO-701 study guide - "Data exfiltration is the unauthorized transfer of data outside an organization and is a significant conern."
Honeybadge 👍 1 Selected: B
This question is worded terribly as it isn't noted that the department is using shadow IT. One shouldn't just assume they are using unauthorized software or hardware. Or I could assume since they aren't using a VPN to provide them a secure tunnel when accessing company resources, they were compromised causing data to be exfiltrated. They are just simply not using their VPN to access authorized company services and systems. This seems to be more of a policy enforcement issue then anything.
jsmthy 👍 3 Selected: D
Using unauthorized software, eh Dave? The scenario may imply the use of an unofficial VPN for the sake of carrying out Espionage or Data Exfiltration, but there is no sign of it. The threat is the VPN rather the user or the data. Additionally, it doesn't seem like the nation-state attack would fit since the hallmarks of such an attack aren't present (lots of funding, firmware-level bugs, unique spyware, social engineering).
MarDog 👍 3
Shadow IT is the use of IT-related hardware or software by a department or individual without the knowledge of the IT or security group within the organization.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Shadow IT Adoption

The scenario directly describes Shadow IT, which refers to hardware, software, or network services procured and utilized by employees without explicit approval from the organization’s IT or security teams. In this case, the Research and Development department is circumventing the mandated corporate VPN to access internal resources. While their intention may be productivity or convenience, bypassing approved security channels creates unmanaged exposure, violates compliance policies, and introduces unvetted vulnerabilities into the enterprise environment.

Why the Other Options Are Incorrect

  • Espionage (A) implies deliberate, covert intelligence gathering, typically by insiders or external actors stealing trade secrets. There is absolutely no indication of malicious intent or secret surveillance in the prompt.
  • Data Exfiltration (B) requires concrete evidence of unauthorized data movement outside the organization. As multiple community members noted, merely skipping a VPN does not automatically mean data is being stolen; it is a control violation, not necessarily a theft event.
  • Nation-State Attack (C) involves highly sophisticated, state-sponsored campaigns targeting critical infrastructure or government entities. This scenario lacks the funding, specialized tools, and strategic objectives characteristic of such advanced persistent threats.

Expert Takeaway & Community Validation

The CompTIA exam heavily penalizes assumption-based answers. Test-takers must strictly adhere to the facts presented: the prompt highlights a process and control bypass, not an active threat or data loss event. The overwhelming community consensus (85% voting D) aligns with official study materials, which classify unsanctioned resource access as a governance and operational risk rather than an immediate incident response scenario.

Official Reference

Exam Strategy

Always anchor your answer strictly to the facts presented in the scenario; never assume malicious intent or data loss unless explicitly stated. When employees bypass IT protocols for convenience, prioritize risk management and governance concepts like Shadow IT over incident response or threat actor classifications.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide