Question 1 of 30
Elara, an intelligence analyst working with IBM i2 Analyst\'s Notebook V8.9, is investigating a complex insider threat scenario within a global logistics firm. She has ingested terabytes of network flow data, employee access logs, and internal communication transcripts. Initial analysis using standard link analysis techniques suggests a pattern of unusual data transfers originating from a specific department during off-peak hours. However, a recent organizational restructuring has led to significant changes in team responsibilities and access privileges within that department, introducing a layer of ambiguity into her established hypotheses. Furthermore, the firm\'s IT infrastructure is undergoing a phased migration to a new cloud-based system, meaning the data she is analyzing spans multiple environments with varying logging capabilities. Considering these dynamic and often unclear circumstances, which approach best reflects Elara\'s need to effectively utilize Analyst\'s Notebook V8.9 while demonstrating key behavioral competencies such as adaptability, problem-solving, and communication?
Iteratively refine analytical hypotheses by incorporating new contextual information from the organizational changes, exploring alternative data sources for corroboration, and adjusting visualization parameters to highlight evolving patterns of activity, while preparing concise, fact-based summaries for the security oversight committee.
Focus exclusively on the initially identified anomalous data transfers, meticulously documenting each instance and building a detailed case based on the original dataset, assuming the organizational changes are incidental and do not fundamentally alter the threat landscape.
Broaden the scope of the investigation to include all employees within the affected division, regardless of their initial connection to the anomalies, and request additional system-wide audit logs, delaying the reporting of preliminary findings until a comprehensive, albeit potentially unfocused, picture emerges.
Prioritize the analysis of the new cloud infrastructure logs, assuming they will provide a clearer and more definitive audit trail, and temporarily de-emphasize the older network flow and access logs until the migration is fully complete, to avoid data inconsistencies.

Preparing for ISO/IEC 27001 Transition Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free