CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
An employee uses a personal cloud storage account to sync work files because the corporate file-sharing tool is slow, without informing the IT department. This practice creates a security risk primarily due to which threat vector?
- AShadow IT
- BWatering hole attack
- CSupply chain compromise
- DBusiness email compromise
Show answer & explanationAnswer & explanation
Correct answer: A. Shadow IT
Unauthorized use of unsanctioned applications or services by employees to bypass approved corporate tools is known as shadow IT, which creates blind spots for security monitoring and data loss prevention.
Why the other options are wrong
- B. A watering hole attack compromises a website frequently visited by targets, unrelated here.
- C. Supply chain compromise involves third-party vendors/software being compromised, not employee tool choice.
- D. BEC involves impersonating executives to defraud a company via email, not personal tool usage.
Shadow IT
The use of unauthorized applications, devices, or services within an organization without the knowledge or approval of the IT department.
- Creates visibility gaps for security teams
- Often driven by convenience or perceived inefficiency of approved tools
- Mitigated by CASB solutions, policy enforcement, and user education
Memory trick: Shadows hide in the cloud where IT can't see.