โ† All CDPSE Flashcard Decks

Incident Response Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response flashcards as text
  1. During a ransomware attack, the attacker claims to have exfiltrated personal data before encrypting it. Under CCPA, what obligation may this trigger?

    Answer: Notification to affected California residents if the data meets breach definition criteria

    CCPA requires notification to California residents when their personal information is subject to unauthorized access and exfiltration that meets the breach definition.

  2. What is the purpose of a privacy incident 'severity classification matrix'?

    Answer: To prioritize incident response resources based on potential harm to data subjects

    A severity classification matrix helps teams rapidly assess risk to data subjects and allocate response resources proportionately.

  3. Which of the following should be documented in an incident response log to support regulatory accountability?

    Answer: Timestamps, actions taken, decisions made, and personnel involved

    A detailed incident log with timestamps, actions, decisions, and personnel creates the audit trail required to demonstrate regulatory accountability.

  4. A healthcare organization experiences a breach affecting 600 individuals' PHI. Under HIPAA Breach Notification Rule, when must HHS be notified?

    Answer: Within 60 days of the end of the calendar year in which the breach occurred

    For breaches affecting fewer than 500 individuals, HIPAA requires HHS notification within 60 days of the end of the calendar year in which the breach is discovered.

  5. A privacy engineer is designing an incident response workflow. Which tool or process best supports rapid identification of what personal data was compromised?

    Answer: A current and accurate data inventory/mapping

    An accurate data inventory and map allows the response team to quickly determine what categories of personal data exist in affected systems.

  6. After resolving a privacy incident, what is the MOST important action for long-term privacy program improvement?

    Answer: Conducting a post-incident review and updating policies and controls

    A post-incident review identifies gaps, updates controls, and feeds lessons learned back into policies to strengthen the privacy program.

  7. Which type of incident MOST directly triggers privacy breach notification obligations?

    Answer: Unauthorized access to a database containing unencrypted Social Security Numbers

    Unauthorized access to unencrypted personal data such as Social Security Numbers constitutes a reportable breach under virtually all privacy frameworks.