企業のセキュリティ チームは、リソースの不適切な使用 (オフィス内のワークステーションにクリプトマイナーをインストールする従業員など) に関する報告ポリシーのセクションを更新しています。セキュリティチームのほかに、
業界のベストプラクティスに従うために、次のグループのうち最初に問題をエスカレーションする必要がありますか?
正解:C
The correct answer is C. Legal department.
According to the CompTIA Cybersecurity Analyst (CySA+) certification exam objectives, one of the tasks for a security analyst is to "report and escalate security incidents to appropriate stakeholders and authorities" 1. This includes reporting any inappropriate use of resources, such as installing cryptominers on workstations, which may violate the company's policies and cause financial and reputational damage. The legal department is the most appropriate group to escalate this issue to first, as they can advise on the legal implications and actions that can be taken against the employee. The legal department can also coordinate with other groups, such as law enforcement, help desk, or board members, as needed. The other options are not the best choices to escalate the issue to first, as they may not have the authority or expertise to handle the situation properly.