350-201 · Question #115
A security engineer discovers that a spreadsheet containing confidential information for nine of their employees was fraudulently posted on a competitor's website. The spreadsheet contains names…
The correct answer is D. Engage the legal department to explore action against the competitor that posted the. When confidential employee PII has already been fraudulently published on a competitor's site, engaging the legal department is the most actionable next step to compel removal and pursue remedies.
Question
A security engineer discovers that a spreadsheet containing confidential information for nine of their employees was fraudulently posted on a competitor's website. The spreadsheet contains names, salaries, and social security numbers. What is the next step the engineer should take in this investigation?
Options
- ADetermine if there is internal knowledge of this incident.
- BCheck incoming and outgoing communications to identify spoofed emails.
- CDisconnect the network from Internet access to stop the phishing threats and regain control.
- DEngage the legal department to explore action against the competitor that posted the
How the community answered
(30 responses)- A13% (4)
- B7% (2)
- C3% (1)
- D77% (23)
Why each option
When confidential employee PII has already been fraudulently published on a competitor's site, engaging the legal department is the most actionable next step to compel removal and pursue remedies.
Checking for internal knowledge is a useful investigation step but does not address the immediate harm of publicly exposed employee PII that requires urgent remediation.
Reviewing communications for spoofed emails investigates a phishing vector unrelated to the incident, which involves data already posted on an external website.
Disconnecting from the internet would not remove data already hosted on the competitor's site and would cause unnecessary business disruption without addressing the root harm.
Because the data - including SSNs, salaries, and names - is already publicly posted, containment at the network level is no longer possible, and legal intervention is required to compel the competitor to remove it and to explore civil or criminal liability. Involving legal counsel also preserves the chain of custody for any evidence needed in litigation and ensures the organization meets breach notification obligations tied to exposed PII.
Concept tested: Incident response prioritization for PII data breach with external publication
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.