44. An accounting employee recently used software that was not approved by the company. Which of the following risks does this most likely represent?
Answer: C
Shadow IT
The scenario described represents a situation of Shadow IT, where employees use unauthorized software that is not sanctioned by their organization. This practice can lead to various security vulnerabilities and compliance issues, as the company may not have control or visibility over these tools.
A) Unskilled attacker
This option refers to individuals lacking the expertise to carry out effective attacks on systems or data. It is not applicable here, as the issue revolves around the use of unauthorized software rather than an attacker's skill level.
B) Hacktivist
Hacktivists are individuals or groups that use hacking to promote political agendas or social change. This choice is not relevant to the situation, which does not involve motives related to activism or protest but rather a breach of company policy regarding software use.
C) Shadow IT
Shadow IT is the use of information technology systems, devices, software, applications, and services without explicit IT department approval. This directly applies to the situation, highlighting the risks associated with employees using unapproved software, which can lead to data breaches and loss of compliance.
D) Supply chain
Supply chain risks pertain to vulnerabilities within the network of suppliers and partners that can affect the security of a company's operations. This option does not fit the context, as the focus is on an individual employee's unauthorized software usage rather than external dependencies.
Conclusion
The correct answer is Shadow IT, as it specifically addresses the risks of using unapproved software within an organization. All other options fail to capture the essence of the situation, which revolves around internal policy violations rather than external threats or motivations. Understanding Shadow IT is crucial for maintaining security and compliance in any organizational setting.