nerdexam
F5

401 · Question #24

What is the appropriate response when dealing with a data breach incident?

The correct answer is C. Notify affected individuals. Notifying affected individuals (C) is the legally and ethically required response to a data breach - it allows people to take protective action (change passwords, monitor accounts, freeze credit) and is mandated by regulations like GDPR, HIPAA, and various state breach…

Section 6: Threat Management and Incident Response

Question

What is the appropriate response when dealing with a data breach incident?

Options

  • ADelete all system logs to cover tracks
  • BContinue regular operations without any changes
  • CNotify affected individuals
  • DIgnore the breach and hope it goes unnoticed

How the community answered

(42 responses)
  • A
    17% (7)
  • B
    7% (3)
  • C
    71% (30)
  • D
    5% (2)

Explanation

Notifying affected individuals (C) is the legally and ethically required response to a data breach - it allows people to take protective action (change passwords, monitor accounts, freeze credit) and is mandated by regulations like GDPR, HIPAA, and various state breach notification laws.

Why the distractors fail:

  • A (delete logs) is obstruction of evidence and likely illegal - logs are critical for forensic investigation and regulatory compliance.
  • B (continue normally) ignores the breach entirely, compounding harm and violating notification obligations.
  • D (ignore and hope) is the same failure as B but worse - "hoping" implies awareness with deliberate inaction, which maximizes legal and reputational damage.

Memory tip: Think "NOTIFY = NINE reasons to act" - Notify Is Not Your Enemy. Transparency is always the right move in breach response; every wrong answer here is some form of hiding or ignoring the problem.

Topics

#data breach response#breach notification#incident handling

Community Discussion

No community discussion yet for this question.

Full 401 Practice