โ† All CDPSE Flashcard Decks

Incident Response Flashcards

7 cards from real CDPSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response flashcards as text
  1. Which NIST framework phase corresponds most closely to identifying that a privacy incident has occurred and classifying its scope?

    Answer: Detection and Analysis

    The Detection and Analysis phase of the NIST incident response lifecycle covers identifying, classifying, and characterizing the scope of an incident.

  2. A breach involves the unauthorized disclosure of 50,000 patient records. The organization's DPA contact list is outdated. What risk does this create?

    Answer: Missed regulatory notification deadlines due to inability to reach the correct authority

    Outdated regulatory contact information can cause the organization to miss mandatory notification windows, resulting in additional violations and penalties.

  3. Under a data processing agreement, a processor discovers a breach at 6 PM Friday. When must they notify the controller under GDPR?

    Answer: Without undue delay after becoming aware

    GDPR requires processors to notify controllers without undue delay after becoming aware of a breach, enabling the controller to meet its own 72-hour notification obligation.

  4. Which privacy engineering principle, if applied before an incident occurs, MOST reduces the volume of data exposed during a breach?

    Answer: Data minimization

    Data minimization limits the collection and retention of personal data, directly reducing the number of records and fields that can be exposed in a breach.

  5. An incident response team concludes that a breach was caused by an employee who mishandled data without malicious intent. What corrective action is MOST appropriate from a privacy program perspective?

    Answer: Review and strengthen training, access controls, and data handling procedures

    Non-malicious insider incidents signal gaps in training and controls; the appropriate response is to improve safeguards rather than pursue punitive action alone.

  6. A privacy breach notification letter to affected individuals must NOT include which of the following under most regulatory frameworks?

    Answer: Speculation about who specifically accessed the data without confirmed evidence

    Notifications should include confirmed facts; speculating about specific unauthorized parties without evidence can mislead individuals and create legal liability.

  7. Which of the following scenarios would MOST likely qualify for the 'risk-based exception' that avoids mandatory breach notification under GDPR?

    Answer: Encrypted laptop with a strong key lost during business travel, with no evidence of decryption

    When data is protected by strong encryption and the key is not compromised, the breach is unlikely to result in a risk to individuals, potentially eliminating the notification obligation.