CDPSE Incident Response 4 — Questions and Answers
Question 1: A privacy officer receives a credible tip that an employee has been emailing customer personal data to a personal account. Which incident response step should occur FIRST?
- Notify all affected customers immediately
- Preserve evidence by capturing email logs before the employee is confronted (Correct answer)
- Delete the employee's account to prevent further exfiltration
- Issue a public press release disclosing the potential breach
Correct answer: Preserve evidence by capturing email logs before the employee is confronted
Preserving forensic evidence before taking containment or notification actions ensures the organization has an accurate record for investigation and legal purposes.
Question 2: Under GDPR Article 34, when must data controllers notify affected individuals directly about a breach?
- In all cases, regardless of risk level
- Only when requested by the supervisory authority
- When the breach is likely to result in a high risk to rights and freedoms of natural persons (Correct answer)
- Only when more than 1,000 individuals are affected
Correct answer: When the breach is likely to result in a high risk to rights and freedoms of natural persons
GDPR Article 34 requires direct notification to individuals only when the breach is likely to result in a high risk to their rights and freedoms.
Question 3: A privacy engineer recommends 'pseudonymization' as a post-breach control. What is the primary privacy benefit of this technique?
- It permanently deletes personal data from affected systems
- It reduces re-identification risk so future exposure causes less harm (Correct answer)
- It automatically notifies regulators on behalf of the organization
- It transfers liability for breaches to the data processor
Correct answer: It reduces re-identification risk so future exposure causes less harm
Pseudonymization reduces the risk that exposed data can be directly linked to individuals, limiting harm if a future breach occurs.
Question 4: Which incident response role is MOST responsible for determining whether a privacy breach notification obligation exists?
- IT Security Analyst
- Chief Privacy Officer or Privacy Counsel (Correct answer)
- Marketing Director
- System Administrator
Correct answer: Chief Privacy Officer or Privacy Counsel
The Chief Privacy Officer or Privacy Counsel interprets applicable privacy laws to determine whether a breach triggers mandatory notification obligations.
Question 5: An organization uses a cloud service provider to store personal data. The CSP experiences a breach. Under GDPR, which party must notify the supervisory authority?
- The CSP (processor) must notify the supervisory authority directly
- The organization (controller) must notify the supervisory authority (Correct answer)
- The data subject must notify the supervisory authority
- No notification is required when a processor causes the breach
Correct answer: The organization (controller) must notify the supervisory authority
The controller holds the notification obligation under GDPR; the processor must notify the controller without undue delay so the controller can meet its obligations.
Question 6: What is the primary purpose of a 'tabletop exercise' in the context of privacy incident response?
- To test the physical security of server rooms
- To practice decision-making and coordination for hypothetical breach scenarios (Correct answer)
- To audit vendor contracts for data processing clauses
- To perform penetration testing on production systems
Correct answer: To practice decision-making and coordination for hypothetical breach scenarios
Tabletop exercises simulate realistic breach scenarios so teams can rehearse decisions, communications, and coordination before a real incident occurs.
Question 7: A financial services company discovers a breach affecting account numbers. Which factor MOST determines whether individual notification is required under US state breach laws?
- The age of the data at time of breach
- Whether the account numbers were combined with other data elements like SSN or access codes (Correct answer)
- The market capitalization of the company
- Whether the breach occurred on a weekend
Correct answer: Whether the account numbers were combined with other data elements like SSN or access codes
Most US state breach laws define a reportable breach as exposure of account numbers only when combined with security codes, PINs, passwords, or similar data elements.
A privacy officer receives a credible tip that an employee has been emailing customer personal data to a personal account.
Which incident response step should occur FIRST?