401 · Question #24
What is the appropriate response when dealing with a data breach incident?
The correct answer is C. Notify affected individuals. Notifying affected individuals (C) is the legally and ethically required response to a data breach - it allows people to take protective action (change passwords, monitor accounts, freeze credit) and is mandated by regulations like GDPR, HIPAA, and various state breach…
Question
What is the appropriate response when dealing with a data breach incident?
Options
- ADelete all system logs to cover tracks
- BContinue regular operations without any changes
- CNotify affected individuals
- DIgnore the breach and hope it goes unnoticed
How the community answered
(42 responses)- A17% (7)
- B7% (3)
- C71% (30)
- D5% (2)
Explanation
Notifying affected individuals (C) is the legally and ethically required response to a data breach - it allows people to take protective action (change passwords, monitor accounts, freeze credit) and is mandated by regulations like GDPR, HIPAA, and various state breach notification laws.
Why the distractors fail:
- A (delete logs) is obstruction of evidence and likely illegal - logs are critical for forensic investigation and regulatory compliance.
- B (continue normally) ignores the breach entirely, compounding harm and violating notification obligations.
- D (ignore and hope) is the same failure as B but worse - "hoping" implies awareness with deliberate inaction, which maximizes legal and reputational damage.
Memory tip: Think "NOTIFY = NINE reasons to act" - Notify Is Not Your Enemy. Transparency is always the right move in breach response; every wrong answer here is some form of hiding or ignoring the problem.
Topics
Community Discussion
No community discussion yet for this question.