"Insider" doesn't always mean a saboteur. CCST often asks you to distinguish these three.
Deliberately harms the org. Disgruntled employee, departing employee taking IP, someone planted by a competitor or nation-state.
Means no harm but causes it anyway. Falls for phishing, emails files to the wrong address, leaves a laptop in a cab. The most common type.
A legitimate account that an outside attacker has taken over (stolen creds, malware). The "insider" is really an outsider wearing the insider's badge.