โ† All CDPSE Flashcard Decks

Incident Response Flashcards

6 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Incident Response flashcards as text
  1. An analyst detects unusual outbound traffic from a server storing customer PII, suggesting potential data exfiltration. According to the NIST incident response lifecycle, what is the IMMEDIATE next step after this initial detection?

    Answer: Analyze the event to understand its scope, nature, and impact.

    According to the NIST incident response lifecycle, the phase immediately following 'Detection' is 'Analysis'. Before taking containment actions like isolating the server or making notifications, the response team must first analyze the event to confirm it is a genuine incident, understand the type and volume of data involved, and assess the potential impact. This analysis informs all subsequent steps, ensuring the response is proportional and effective.

  2. An organization is creating its privacy incident response plan. Which of the following components is MOST critical for ensuring a coordinated and effective real-time response during a crisis?

    Answer: A predefined communication and escalation matrix with clearly defined roles and responsibilities.

    During a high-stress privacy incident, clear communication and established authority are paramount to prevent chaos. A predefined communication and escalation matrix that outlines roles (like an incident commander), responsibilities, and who to contact for specific issues ensures a coordinated, efficient, and timely response. While other elements are important parts of a mature privacy program, the communication and roles matrix is the foundational component for managing the response itself.

  3. Under the GDPR, which of the following is the PRIMARY trigger that elevates a privacy incident to a notifiable data breach requiring communication to a supervisory authority within 72 hours?

    Answer: The incident is likely to result in a risk to the rights and freedoms of natural persons.

    According to GDPR Article 33, the core criterion for mandatory notification to the supervisory authority is whether the breach is "likely to result in a risk to the rights and freedoms of natural persons." If the breach is unlikely to pose such a risk, notification is not required. The cause, number of subjects, and type of data are factors in assessing the risk, but the likelihood of risk itself is the legal trigger for notification.

  4. A privacy engineer discovers that an internal sales dashboard, which aggregates unanonymized customer data, has been misconfigured and is publicly accessible on the internet. What is the MOST appropriate immediate action to contain this incident?

    Answer: Immediately revoke public access and restrict it to authorized personnel.

    The primary goal of the containment phase in incident response is to stop the ongoing unauthorized access or disclosure and prevent further damage. Immediately revoking public access directly addresses the cause of the exposure and is the fastest, most effective way to contain the incident. Other actions like analysis (identifying exposed data) and notification preparation are critical but follow immediately after the bleeding has been stopped.

  5. Following the complete resolution of a significant data breach, what is the MOST important activity in the post-incident phase of the response lifecycle?

    Answer: Conducting a 'lessons learned' review to identify the root cause and improve future responses.

    The post-incident phase is crucial for continuous improvement and maturing the organization's resilience. Conducting a 'lessons learned' or post-mortem review allows the team to perform a root cause analysis, identify weaknesses in controls or procedures, and implement corrective actions to prevent similar incidents from recurring. This activity provides the greatest long-term value for the privacy program.

  6. A database administrator unintentionally runs a script that discloses sensitive employee salary data to a wide group of project managers who are not authorized to view it. The data never left the company's internal network. Which statement BEST describes this event?

    Answer: This is a privacy incident because personal data was disclosed to unauthorized individuals.

    A privacy incident is any unauthorized use or disclosure of personal data. It is not limited to external attacks or data leaving the network. In this scenario, the disclosure to unauthorized internal recipients constitutes a breach of confidentiality, making it a privacy incident, regardless of intent. While it is also a security incident, its classification as a privacy incident is key because it involves personal data.