CDPSE Incident Response 5 — Questions and Answers
Question 1: Which NIST framework phase corresponds most closely to identifying that a privacy incident has occurred and classifying its scope?
- Preparation
- Detection and Analysis (Correct answer)
- Containment, Eradication, and Recovery
- Post-Incident Activity
Correct answer: Detection and Analysis
The Detection and Analysis phase of the NIST incident response lifecycle covers identifying, classifying, and characterizing the scope of an incident.
Question 2: A breach involves the unauthorized disclosure of 50,000 patient records. The organization's DPA contact list is outdated. What risk does this create?
- Lower encryption overhead on affected systems
- Missed regulatory notification deadlines due to inability to reach the correct authority (Correct answer)
- Automatic waiver of fines under safe harbor provisions
- Reduced number of data subjects entitled to compensation
Correct answer: Missed regulatory notification deadlines due to inability to reach the correct authority
Outdated regulatory contact information can cause the organization to miss mandatory notification windows, resulting in additional violations and penalties.
Question 3: Under a data processing agreement, a processor discovers a breach at 6 PM Friday. When must they notify the controller under GDPR?
- Within 72 hours of the supervisory authority's business hours
- Without undue delay after becoming aware (Correct answer)
- By the following Monday morning
- Only after completing their own internal investigation
Correct answer: Without undue delay after becoming aware
GDPR requires processors to notify controllers without undue delay after becoming aware of a breach, enabling the controller to meet its own 72-hour notification obligation.
Question 4: Which privacy engineering principle, if applied before an incident occurs, MOST reduces the volume of data exposed during a breach?
- Transparency
- Data minimization (Correct answer)
- User consent management
- Privacy notice clarity
Correct answer: Data minimization
Data minimization limits the collection and retention of personal data, directly reducing the number of records and fields that can be exposed in a breach.
Question 5: An incident response team concludes that a breach was caused by an employee who mishandled data without malicious intent. What corrective action is MOST appropriate from a privacy program perspective?
- Immediately terminate the employee
- Review and strengthen training, access controls, and data handling procedures (Correct answer)
- File a criminal complaint against the employee
- Reduce the organization's data collection to zero
Correct answer: Review and strengthen training, access controls, and data handling procedures
Non-malicious insider incidents signal gaps in training and controls; the appropriate response is to improve safeguards rather than pursue punitive action alone.
Question 6: A privacy breach notification letter to affected individuals must NOT include which of the following under most regulatory frameworks?
- A description of what personal data was involved
- Steps individuals can take to protect themselves
- Contact information for questions
- Speculation about who specifically accessed the data without confirmed evidence (Correct answer)
Correct answer: Speculation about who specifically accessed the data without confirmed evidence
Notifications should include confirmed facts; speculating about specific unauthorized parties without evidence can mislead individuals and create legal liability.
Question 7: Which of the following scenarios would MOST likely qualify for the 'risk-based exception' that avoids mandatory breach notification under GDPR?
- Unencrypted USB drive containing names and medical records lost in a parking lot
- Encrypted laptop with a strong key lost during business travel, with no evidence of decryption (Correct answer)
- Database backup emailed to the wrong external recipient
- Employee sharing customer email list with a competitor
Correct answer: Encrypted laptop with a strong key lost during business travel, with no evidence of decryption
When data is protected by strong encryption and the key is not compromised, the breach is unlikely to result in a risk to individuals, potentially eliminating the notification obligation.
Which NIST framework phase corresponds most closely to identifying that a privacy incident has occurred and classifying its scope?