Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 275 discussion

Actual exam question from ISC's CISSP
Question #: 275
Topic #: 1
[All CISSP Questions]

What type of database attack would allow a customer service employee to determine quarterly sales results before they are publicly announced?

  • A. Inference
  • B. Aggregation
  • C. Polyinstantiation
  • D. Data mining
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
[Removed]
Highly Voted 2 years, 1 month ago
Selected Answer: A
An inference as the attacker used several pieces of generic nonsensitive information to determine or learn specific sensitive value.
upvoted 11 times
jackdryan
1 year, 6 months ago
A is correct
upvoted 3 times
...
...
franbarpro
Highly Voted 2 years, 1 month ago
Selected Answer: A
The question says - What type of database attack. "D" Data mining is not an attack. So, am going with "A" on this one.
upvoted 7 times
...
deeden
Most Recent 3 months, 2 weeks ago
Selected Answer: A
Aggregation attacks involve collecting and combining data from multiple sources to form a detailed dataset, which might not be sensitive in isolation but becomes significant when compiled together. Inference then is the process of analyzing this aggregated data to draw conclusions or predict future outcomes. Thus, while aggregation is about assembling the data, inference is about interpreting the assembled data to extract meaningful insights or conclusions.
upvoted 1 times
...
CCNPWILL
5 months, 3 weeks ago
Selected Answer: A
Answer is A. Aggregating information to discover new information. inference.
upvoted 1 times
...
Soleandheel
11 months, 2 weeks ago
A. Inference Inference attacks involve an attacker making educated guesses or inferences about sensitive information by analyzing less sensitive data or clues that are available to them. In this scenario, the employee may use their access to less sensitive data or information within the database to infer or deduce quarterly sales results that have not yet been publicly announced.
upvoted 1 times
...
thanhlb
1 year, 1 month ago
Selected Answer: B
B. Aggregation. Aggregation is a technique that involves combining data from different sources or levels of granularity to infer sensitive information that is not directly accessible1. For example, a customer service employee might be able to access individual sales records for each customer, but not the total sales figures for each quarter. However, by aggregating the sales records by date, product, or region, the employee might be able to estimate the quarterly sales results before they are officially released2. An inference attack is a technique that involves analyzing data to gain knowledge about a subject or database without directly accessing it3. For example, an inference attack might use statistical methods, machine learning models, or logical reasoning to deduce sensitive information from seemingly innocuous data. An inference attack does not necessarily involve aggregation, and it might target individual records rather than aggregate values.
upvoted 3 times
...
Tygrond87
1 year, 6 months ago
Selected Answer: B
In summary, inference is about making generalizable conclusions about a population from a sample, while aggregation is about summarizing and simplifying complex data sets into summary values or categories.
upvoted 1 times
...
Watcher009
1 year, 7 months ago
Selected Answer: A
Data mining can be used for a wide range of purposes, including market research and fraud detection, but it does not involve a specific attack on a database to gain unauthorized access to information.
upvoted 2 times
...
Goseu
1 year, 7 months ago
Selected Answer: B
It’s aggregation attack , an employee simply adds non sensitive pieces of info to create sensitive information . There is no deduction . Inference and aggregation are always very close and confusing.
upvoted 3 times
...
crazywai1221
1 year, 8 months ago
Selected Answer: A
The type of database attack that would allow a customer service employee to determine quarterly sales results before they are publicly announced is Inference. Inference is a type of database attack in which an attacker uses available data to infer or deduce additional sensitive information. In the given scenario, the customer service employee might have access to some data in the database that could provide clues about the quarterly sales results. By analyzing this data, the employee might be able to infer the actual sales results before they are publicly announced. Aggregation is a type of attack in which an attacker combines multiple sources of data to gain access to sensitive information. Polyinstantiation is a type of attack in which an attacker creates multiple instances of an object with different security levels, causing a breach of integrity. Data mining is a process of analyzing data to discover patterns and relationships. In conclusion, Inference is the type of database attack that would allow a customer service employee to determine quarterly sales results before they are publicly announced.
upvoted 3 times
...
RVoigt
1 year, 9 months ago
Selected Answer: A
The CISSP Official Study Guide includes a direct correlation: "A commonly cited example of an inference attack is that of the accounting clerk at a large corporation who is allowed to retrieve the total amount the company spends on salaries for use in a top-level report but is not allowed to access the salaries of individual employees. The accounting clerk often has to prepare those reports with effective dates in the past and so is allowed to access the total salary amounts for any day in the past year. Say, for example, that this clerk must also know the hiring and termination dates of various employees and has access to this information. This opens the door for an inference attack. If an employee was the only person hired on a specific date, the accounting clerk can now retrieve the total salary amount on that date and the day before and deduce the salary of that particular employee—sensitive information that the user would not be permitted to access directly."
upvoted 2 times
...
Dee83
1 year, 10 months ago
D. Data mining Data mining is the process of discovering patterns and knowledge from large data sets. In this scenario, a customer service employee could use data mining techniques to extract information from the organization's database, such as quarterly sales results, before they are publicly announced. This would allow the employee to gain unauthorized access to sensitive information, potentially giving them an unfair advantage over other employees or external parties.
upvoted 1 times
...
oudmaster
1 year, 11 months ago
Selected Answer: A
Inference requires thinking and correlation part. And this is what the question scenario about. Inference is the ability to derive information that is not explicitly available. ! Data mining is requires special tools to analyze, human themselves cannot do it. Aggregation is when individual pieces of data are combined to create a bigger picture that may have greater sensitivity than individual parts.
upvoted 1 times
...
[Removed]
1 year, 11 months ago
The most correct is what they want. Thus I’d go with A which is a more precise data mining.
upvoted 1 times
...
Ivanchun
1 year, 11 months ago
Selected Answer: A
A, use non sensitive information to gain the sensitive information
upvoted 1 times
...
rdy4u
2 years ago
Selected Answer: A
An Inference Attack is a data mining technique performed by analyzing data in order to illegitimately gain knowledge about a subject or database. A subject's sensitive information can be considered as leaked if an adversary can infer its real value with a high confidence. https://en.wikipedia.org/wiki/Inference_attack
upvoted 1 times
...
Nickname53796
2 years, 1 month ago
Selected Answer: A
Imma say inference. Because it’s a cust service rep. I doubt he knows many sql commands. Could be wrong.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...