Data Breach Response & Incident Management Flashcards
6 cards from real PLC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Data Breach Response & Incident Management flashcards as text
An organization's incident response plan (IRP) should be tested using tabletop exercises at minimum how often, according to NIST SP 800-61 guidance?
Answer: Annually
NIST SP 800-61 recommends that incident response plans be reviewed and tested at least annually to ensure effectiveness and currency.
Which term describes the process of preserving digital evidence in a forensically sound manner following a data breach?
Answer: Chain of custody
Chain of custody refers to the documented process of collecting, preserving, and handling digital evidence so it remains admissible and unaltered.
A US company experiences a breach affecting EU residents' data. Under GDPR, if the breach is unlikely to result in a risk to individuals' rights, the company must:
Answer: Document the breach internally without notifying authorities
GDPR Article 33(1) states that breaches unlikely to result in risk to individuals' rights need not be reported to supervisory authorities but must be documented internally.
Which phase of NIST's incident response lifecycle involves activities to stop the spread of an incident and prevent further damage?
Answer: Containment, Eradication, and Recovery
The Containment, Eradication, and Recovery phase focuses on stopping the incident spread, removing the threat, and restoring normal operations.
What is the purpose of a 'post-mortem' or 'lessons learned' meeting after a data breach incident?
Answer: To identify what worked, what failed, and how to improve future response
Post-incident reviews identify gaps in preparation, response, and recovery to strengthen the organization's future incident handling capabilities.
Under FTC Act Section 5, failure to maintain reasonable security measures that leads to a data breach can be considered:
Answer: An unfair or deceptive trade practice
The FTC has consistently held that inadequate data security practices that result in consumer harm constitute unfair or deceptive acts or practices under FTC Act Section 5.