A Salesforce Service Provider discovers that a customer's org has an API integration that has been transmitting data to an unauthorized external endpoint for 30 days. What is the FIRST step in the incident response process?
-
A
Immediately revoke all API keys in the affected org
-
B
Contain the breach by disabling the compromised integration
-
C
Notify all affected customers within 24 hours
-
D
Perform a full forensic audit before taking any action