CAS-002 · Question #30
CAS-002 Question #30: Real Exam Question with Answer & Explanation
The correct answer is C: Incident response. The helpdesk treated the lost device as a simple equipment replacement issue and closed the ticket without recognizing it as a security incident (data breach). Proper incident response procedures require identifying, reporting, containing, and escalating security incidents-includ
Question
Options
- AE-Discovery
- BData handling
- CIncident response
- DData recovery and storage
Explanation
The helpdesk treated the lost device as a simple equipment replacement issue and closed the ticket without recognizing it as a security incident (data breach). Proper incident response procedures require identifying, reporting, containing, and escalating security incidents-including lost devices containing sensitive data-to the appropriate parties (security team, legal, compliance, potentially regulators). The failure was in not following the incident response process. E-Discovery (A) is the legal process of locating electronic evidence for litigation. Data handling (B) governs how data is classified, stored, and transmitted-relevant but not the cause of the reporting failure. Data recovery and storage (D) pertains to backup and retrieval of data, not to reporting security incidents.
Community Discussion
No community discussion yet for this question.