nerdexam
ExamsCAS-002Questions#30
CompTIA

CAS-002 · Question #30

CAS-002 Question #30: Real Exam Question with Answer & Explanation

The correct answer is C: Incident response. The helpdesk treated the lost device as a simple equipment replacement issue and closed the ticket without recognizing it as a security incident (data breach). Proper incident response procedures require identifying, reporting, containing, and escalating security incidents-includ

Question

The Chief Executive Officer (CEO) of a corporation purchased the latest mobile device and connected it to the internal network. The CEO proceeded to download sensitive financial documents through their email. The device was then lost in transit to a conference. The CEO notified the company helpdesk about the lost device and another one was shipped out, after which the helpdesk ticket was closed stating the issue was resolved. This data breach was not properly reported due to insufficient training surrounding which of the following processes?

Options

  • AE-Discovery
  • BData handling
  • CIncident response
  • DData recovery and storage

Explanation

The helpdesk treated the lost device as a simple equipment replacement issue and closed the ticket without recognizing it as a security incident (data breach). Proper incident response procedures require identifying, reporting, containing, and escalating security incidents-including lost devices containing sensitive data-to the appropriate parties (security team, legal, compliance, potentially regulators). The failure was in not following the incident response process. E-Discovery (A) is the legal process of locating electronic evidence for litigation. Data handling (B) governs how data is classified, stored, and transmitted-relevant but not the cause of the reporting failure. Data recovery and storage (D) pertains to backup and retrieval of data, not to reporting security incidents.

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice