nerdexam
Isaca

CDPSE · Question #81

Which of the following is the PRIMARY objective of privacy incident response?

The correct answer is C. To mitigate the impact of privacy incidents. The primary objective of any incident response process-including privacy incidents-is to contain the incident and reduce harm. Mitigating impact addresses the immediate consequences to affected individuals and the organization. Notifying data subjects (A) is an important legal…

Privacy Governance

Question

Which of the following is the PRIMARY objective of privacy incident response?

Options

  • ATo ensure data subjects impacted by privacy incidents are notified.
  • BTo reduce privacy risk to the lowest possible level
  • CTo mitigate the impact of privacy incidents
  • DTo optimize the costs associated with privacy incidents

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    2% (1)
  • C
    91% (39)
  • D
    2% (1)

Explanation

The primary objective of any incident response process-including privacy incidents-is to contain the incident and reduce harm. Mitigating impact addresses the immediate consequences to affected individuals and the organization. Notifying data subjects (A) is an important legal obligation that occurs during or after response, but notification itself does not reduce harm-it is a means of enabling affected individuals to protect themselves. Reducing risk to the lowest possible level (B) is an ongoing risk management goal, not an incident-specific objective. Cost optimization (D) is a business consideration, not a privacy or security objective.

Topics

#Privacy Incident Response#Incident Management#Mitigation#Breach Response

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice