Answer: Espionage
Answer: Data exfiltration
Answer: Shadow IT
Answer: Zero-day
Answer: CThe correct answer is C. Shadow IT.Shadow IT refers to hardware, software, cloud services, or applications used within an organization without formal approval, review, or oversight by the IT or security department. In this scenario, the department deployed a simulation program without proper vetting, making it an example of shadow IT.This aligns with CompTIA Security+ SY0-701 risk management and governance concepts. Unauthorized or unapproved technology can introduce risks such as data leakage, insecure configurations, licensing violations, compliance issues, privacy concerns, and unsupported software vulnerabilities.Why the other options are incorrect:
Answer: EspionageEspionage involves spying or gathering confidential information for political, competitive, or financial advantage. The question does not indicate spying.
Answer: Data exfiltrationData exfiltration is the unauthorized transfer of data out of an organization. The question only states that unvetted software was deployed.
Answer: Zero-dayA zero-day is a vulnerability that is unknown to the vendor or has no available patch. The question does not describe an unknown vulnerability.Therefore, the best answer is shadow IT.