DA0-001 · Question #373
Which of the following are the first steps a company should take after discovering a data breach? (Choose two.)
The correct answer is B. Notify affected users. C. Assess the breach. After discovering a data breach, the two immediate priorities are assessing the breach (C) to understand its scope, what data was compromised, and how it occurred, and notifying affected users (B) as required by most privacy regulations (e.g., GDPR, HIPAA). Deleting data (A)…
Question
Which of the following are the first steps a company should take after discovering a data breach? (Choose two.)
Options
- ADelete data.
- BNotify affected users.
- CAssess the breach.
- DBack up the system.
- EIssue a press release.
- FDelay reporting.
How the community answered
(31 responses)- A3% (1)
- B77% (24)
- D13% (4)
- F6% (2)
Explanation
After discovering a data breach, the two immediate priorities are assessing the breach (C) to understand its scope, what data was compromised, and how it occurred, and notifying affected users (B) as required by most privacy regulations (e.g., GDPR, HIPAA). Deleting data (A) could destroy forensic evidence. Backing up the system (D) is not the first priority. Issuing a press release (E) may come later but is not an immediate first step. Delaying reporting (F) is often illegal and always harmful.
Topics
Community Discussion
No community discussion yet for this question.