โ† All CDPSE Flashcard Decks

Incident Response Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response flashcards as text
  1. A privacy officer receives a credible tip that an employee has been emailing customer personal data to a personal account. Which incident response step should occur FIRST?

    Answer: Preserve evidence by capturing email logs before the employee is confronted

    Preserving forensic evidence before taking containment or notification actions ensures the organization has an accurate record for investigation and legal purposes.

  2. Under GDPR Article 34, when must data controllers notify affected individuals directly about a breach?

    Answer: When the breach is likely to result in a high risk to rights and freedoms of natural persons

    GDPR Article 34 requires direct notification to individuals only when the breach is likely to result in a high risk to their rights and freedoms.

  3. A privacy engineer recommends 'pseudonymization' as a post-breach control. What is the primary privacy benefit of this technique?

    Answer: It reduces re-identification risk so future exposure causes less harm

    Pseudonymization reduces the risk that exposed data can be directly linked to individuals, limiting harm if a future breach occurs.

  4. Which incident response role is MOST responsible for determining whether a privacy breach notification obligation exists?

    Answer: Chief Privacy Officer or Privacy Counsel

    The Chief Privacy Officer or Privacy Counsel interprets applicable privacy laws to determine whether a breach triggers mandatory notification obligations.

  5. An organization uses a cloud service provider to store personal data. The CSP experiences a breach. Under GDPR, which party must notify the supervisory authority?

    Answer: The organization (controller) must notify the supervisory authority

    The controller holds the notification obligation under GDPR; the processor must notify the controller without undue delay so the controller can meet its obligations.

  6. What is the primary purpose of a 'tabletop exercise' in the context of privacy incident response?

    Answer: To practice decision-making and coordination for hypothetical breach scenarios

    Tabletop exercises simulate realistic breach scenarios so teams can rehearse decisions, communications, and coordination before a real incident occurs.

  7. A financial services company discovers a breach affecting account numbers. Which factor MOST determines whether individual notification is required under US state breach laws?

    Answer: Whether the account numbers were combined with other data elements like SSN or access codes

    Most US state breach laws define a reportable breach as exposure of account numbers only when combined with security codes, PINs, passwords, or similar data elements.