CDPSE Incident Response 3 — Questions and Answers
Question 1: During a ransomware attack, the attacker claims to have exfiltrated personal data before encrypting it. Under CCPA, what obligation may this trigger?
- Mandatory law enforcement referral within 24 hours
- Notification to affected California residents if the data meets breach definition criteria (Correct answer)
- Suspension of all data processing operations
- Automatic regulatory fine of $7,500 per record
Correct answer: Notification to affected California residents if the data meets breach definition criteria
CCPA requires notification to California residents when their personal information is subject to unauthorized access and exfiltration that meets the breach definition.
Question 2: What is the purpose of a privacy incident 'severity classification matrix'?
- To determine the budget allocated for cybersecurity tools
- To prioritize incident response resources based on potential harm to data subjects (Correct answer)
- To rank employees by their involvement in causing incidents
- To categorize data by its monetary value to the organization
Correct answer: To prioritize incident response resources based on potential harm to data subjects
A severity classification matrix helps teams rapidly assess risk to data subjects and allocate response resources proportionately.
Question 3: Which of the following should be documented in an incident response log to support regulatory accountability?
- Names of competing organizations that were not affected
- Timestamps, actions taken, decisions made, and personnel involved (Correct answer)
- Marketing campaign performance during the incident
- Employee salaries of the response team
Correct answer: Timestamps, actions taken, decisions made, and personnel involved
A detailed incident log with timestamps, actions, decisions, and personnel creates the audit trail required to demonstrate regulatory accountability.
Question 4: A healthcare organization experiences a breach affecting 600 individuals' PHI. Under HIPAA Breach Notification Rule, when must HHS be notified?
- Within 24 hours of discovery
- Within 30 days of discovery
- Within 60 days of the end of the calendar year in which the breach occurred (Correct answer)
- Within 72 hours of discovery
Correct answer: Within 60 days of the end of the calendar year in which the breach occurred
For breaches affecting fewer than 500 individuals, HIPAA requires HHS notification within 60 days of the end of the calendar year in which the breach is discovered.
Question 5: A privacy engineer is designing an incident response workflow. Which tool or process best supports rapid identification of what personal data was compromised?
- A firewall traffic dashboard
- A current and accurate data inventory/mapping (Correct answer)
- Employee background check records
- Marketing analytics platform
Correct answer: A current and accurate data inventory/mapping
An accurate data inventory and map allows the response team to quickly determine what categories of personal data exist in affected systems.
Question 6: After resolving a privacy incident, what is the MOST important action for long-term privacy program improvement?
- Immediately deleting all logs related to the incident
- Conducting a post-incident review and updating policies and controls (Correct answer)
- Replacing all affected hardware regardless of cost
- Hiring new staff to handle future incidents
Correct answer: Conducting a post-incident review and updating policies and controls
A post-incident review identifies gaps, updates controls, and feeds lessons learned back into policies to strengthen the privacy program.
Question 7: Which type of incident MOST directly triggers privacy breach notification obligations?
- A server performance degradation that slows application response time
- Unauthorized access to a database containing unencrypted Social Security Numbers (Correct answer)
- A failed login attempt blocked by multi-factor authentication
- An expired SSL certificate on a non-data-collecting landing page
Correct answer: Unauthorized access to a database containing unencrypted Social Security Numbers
Unauthorized access to unencrypted personal data such as Social Security Numbers constitutes a reportable breach under virtually all privacy frameworks.
During a ransomware attack, the attacker claims to have exfiltrated personal data before encrypting it.
Under CCPA, what obligation may this trigger?