PLC Data Breach Response & Incident Management 2 — Questions and Answers
Question 1: An organization's incident response plan (IRP) should be tested using tabletop exercises at minimum how often, according to NIST SP 800-61 guidance?
- Monthly
- Quarterly
- Annually (Correct answer)
- Every two years
Correct answer: Annually
NIST SP 800-61 recommends that incident response plans be reviewed and tested at least annually to ensure effectiveness and currency.
Question 2: Which term describes the process of preserving digital evidence in a forensically sound manner following a data breach?
- Chain of custody (Correct answer)
- Data minimization
- Litigation hold
- Privilege log
Correct answer: Chain of custody
Chain of custody refers to the documented process of collecting, preserving, and handling digital evidence so it remains admissible and unaltered.
Question 3: A US company experiences a breach affecting EU residents' data. Under GDPR, if the breach is unlikely to result in a risk to individuals' rights, the company must:
- Notify the supervisory authority within 72 hours
- Notify affected individuals immediately
- Document the breach internally without notifying authorities (Correct answer)
- Notify both the supervisory authority and individuals within 72 hours
Correct answer: Document the breach internally without notifying authorities
GDPR Article 33(1) states that breaches unlikely to result in risk to individuals' rights need not be reported to supervisory authorities but must be documented internally.
Question 4: Which phase of NIST's incident response lifecycle involves activities to stop the spread of an incident and prevent further damage?
- Detection and Analysis
- Containment, Eradication, and Recovery (Correct answer)
- Post-Incident Activity
- Preparation
Correct answer: Containment, Eradication, and Recovery
The Containment, Eradication, and Recovery phase focuses on stopping the incident spread, removing the threat, and restoring normal operations.
Question 5: What is the purpose of a 'post-mortem' or 'lessons learned' meeting after a data breach incident?
- To assign legal blame to responsible employees
- To identify what worked, what failed, and how to improve future response (Correct answer)
- To draft the customer notification letter
- To calculate financial losses for insurance claims
Correct answer: To identify what worked, what failed, and how to improve future response
Post-incident reviews identify gaps in preparation, response, and recovery to strengthen the organization's future incident handling capabilities.
Question 6: Under FTC Act Section 5, failure to maintain reasonable security measures that leads to a data breach can be considered:
- A criminal offense requiring DOJ prosecution
- An unfair or deceptive trade practice (Correct answer)
- A strict liability tort
- A violation only if negligence is proven
Correct answer: An unfair or deceptive trade practice
The FTC has consistently held that inadequate data security practices that result in consumer harm constitute unfair or deceptive acts or practices under FTC Act Section 5.
An organization's incident response plan (IRP) should be tested using tabletop exercises at minimum how often, according to NIST SP 800-61 guidance?