712-50 · Question #65
A Security Operations Centre (SOC) manager is informed that a database containing highly sensitive corporate strategy information is under attack. Information has been stolen and the database server…
The correct answer is B. The data owner. Option B is correct because the data owner is the individual or role with ultimate accountability for the data's classification, access, and protection - when a breach occurs, they must be notified immediately so they can make informed decisions about risk, remediation, and…
Question
A Security Operations Centre (SOC) manager is informed that a database containing highly sensitive corporate strategy information is under attack. Information has been stolen and the database server was disconnected. Who must be informed of this incident?
Options
- AInternal audit
- BThe data owner
- CAll executive staff
- DGovernment regulators
How the community answered
(53 responses)- A8% (4)
- B85% (45)
- C6% (3)
- D2% (1)
Explanation
Option B is correct because the data owner is the individual or role with ultimate accountability for the data's classification, access, and protection - when a breach occurs, they must be notified immediately so they can make informed decisions about risk, remediation, and required disclosures.
Why the distractors are wrong:
- A (Internal Audit) - Audit may eventually review the incident, but they are not the primary notification target during an active breach; they are a compliance and oversight function, not a data governance authority.
- C (All executive staff) - Notifying all executives is too broad and not a standard incident response obligation; communication is escalated selectively based on role and need-to-know.
- D (Government regulators) - Regulatory notification may be required depending on jurisdiction and data type (e.g., GDPR, HIPAA), but this is a downstream obligation triggered after internal processes - and the question asks who must be informed first, which points inward to the data owner before any external body.
Memory tip: Think of the data owner as the "CEO of the data" - just as you'd tell a business owner their store was robbed before calling anyone else, the data owner is always the first internal call in a data breach.
Topics
Community Discussion
No community discussion yet for this question.