Incident Response Flashcards
7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response flashcards as text
Under the GDPR, what is the maximum time allowed to notify the supervisory authority after becoming aware of a personal data breach?
Answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Which element is MOST critical to include in an initial breach notification to affected individuals?
Answer: Steps individuals can take to protect themselves
Notifications to individuals must include actionable steps they can take to mitigate potential harm to themselves.
A company discovers that encrypted backup tapes containing personal data were lost during shipping. Under most privacy frameworks, what is the FIRST factor to assess?
Answer: Whether the encryption renders the data unintelligible to unauthorized parties
Strong encryption that renders data unintelligible to unauthorized parties may eliminate or reduce the notification obligation under many frameworks.
Which of the following best describes 'containment' in the context of a privacy incident response?
Answer: Limiting further unauthorized access or spread of exposed personal data
Containment focuses on stopping the incident from worsening by limiting further exposure or unauthorized access to personal data.
A privacy engineer is reviewing an incident response plan. Which phase should include updating privacy impact assessments and patching vulnerabilities?
Answer: Post-incident recovery and lessons learned
The post-incident phase involves remediation activities such as updating PIAs, patching vulnerabilities, and improving controls based on lessons learned.
An organization's incident response team discovers that a third-party vendor exposed customer records. Who bears the primary regulatory notification obligation under GDPR?
Answer: The data controller (organization)
Under GDPR, the data controller bears the primary obligation to notify the supervisory authority and data subjects, even when the breach occurred at a processor.
Which metric is MOST useful for evaluating incident response effectiveness from a privacy perspective?
Answer: Mean time to detect and contain a privacy breach
Mean time to detect and contain directly measures the speed and efficiency of the incident response process, minimizing harm to data subjects.