nerdexam
EC-Council

712-50 · Question #65

A Security Operations Centre (SOC) manager is informed that a database containing highly sensitive corporate strategy information is under attack. Information has been stolen and the database server…

The correct answer is B. The data owner. Option B is correct because the data owner is the individual or role with ultimate accountability for the data's classification, access, and protection - when a breach occurs, they must be notified immediately so they can make informed decisions about risk, remediation, and…

IS Management Controls and Auditing Management

Question

A Security Operations Centre (SOC) manager is informed that a database containing highly sensitive corporate strategy information is under attack. Information has been stolen and the database server was disconnected. Who must be informed of this incident?

Options

  • AInternal audit
  • BThe data owner
  • CAll executive staff
  • DGovernment regulators

How the community answered

(53 responses)
  • A
    8% (4)
  • B
    85% (45)
  • C
    6% (3)
  • D
    2% (1)

Explanation

Option B is correct because the data owner is the individual or role with ultimate accountability for the data's classification, access, and protection - when a breach occurs, they must be notified immediately so they can make informed decisions about risk, remediation, and required disclosures.

Why the distractors are wrong:

  • A (Internal Audit) - Audit may eventually review the incident, but they are not the primary notification target during an active breach; they are a compliance and oversight function, not a data governance authority.
  • C (All executive staff) - Notifying all executives is too broad and not a standard incident response obligation; communication is escalated selectively based on role and need-to-know.
  • D (Government regulators) - Regulatory notification may be required depending on jurisdiction and data type (e.g., GDPR, HIPAA), but this is a downstream obligation triggered after internal processes - and the question asks who must be informed first, which points inward to the data owner before any external body.

Memory tip: Think of the data owner as the "CEO of the data" - just as you'd tell a business owner their store was robbed before calling anyone else, the data owner is always the first internal call in a data breach.

Topics

#Incident Response#Data Breach Notification#Data Owner Responsibility#Incident Management

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice