CAS-001 · Question #30
The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and connected it to the internal network. The CEO proceeded to download sensitive financial documents through…
The correct answer is C. Incident response. The helpdesk closed the ticket after replacing the device without recognizing and escalating the situation as a security incident involving a data breach, indicating a failure in incident response training.
Question
The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and connected it to the internal network. The CEO proceeded to download sensitive financial documents through their email. The device was then lost in transit to a conference. The CEO notified the company helpdesk about the lost device and another one was shipped out, after which the helpdesk ticket was closed stating the issue was resolved. This data breach was not properly reported due to insufficient training surrounding which of the following processes?
Options
- AE-Discovery
- BData handling
- CIncident response
- DData recovery and storage
How the community answered
(27 responses)- A4% (1)
- C96% (26)
Why each option
The helpdesk closed the ticket after replacing the device without recognizing and escalating the situation as a security incident involving a data breach, indicating a failure in incident response training.
E-discovery is a legal process for retrieving electronic records for litigation and is not the process that governs how employees report and respond to security incidents involving lost devices.
Data handling covers how data is classified, stored, and transmitted, but the failure here was not in how data was handled before loss - it was in the failure to recognize and report the loss as a security incident.
Incident response procedures define how staff must identify, report, escalate, and document security events such as data breaches caused by lost devices containing sensitive information; the helpdesk staff lacked training on these procedures and treated the situation as a routine device replacement rather than triggering the breach notification and investigation steps required by a proper incident response plan.
Data recovery and storage refers to backup and restoration processes, which are not relevant to the failure to report a breach resulting from a physically lost device.
Concept tested: Incident response procedures for data breach reporting
Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.