What this quiz covers
This quiz focuses on Incident Response And Breach Notification Procedures, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
A healthcare organization experiences a breach of protected health information (PHI). Under HIPAA's Breach Notification Rule, the organization must notify affected individuals within:
CPA Isc Quiz
Practice Incident Response And Breach Notification Procedures in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
This quiz focuses on Incident Response And Breach Notification Procedures, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
A healthcare organization experiences a breach of protected health information (PHI). Under HIPAA's Breach Notification Rule, the organization must notify affected individuals within:
Explanation: HIPAA's Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovering the breach. Answer C is correct. 24 hours (A) is not the HIPAA requirement. 30 days (B) is shorter than required but may satisfy the rule if completed. 90 days post-investigation (D) exceeds the discovery-based 60-day clock.
A company discovers that an employee's laptop containing unencrypted customer data was stolen. Which of the following is the organization's most immediate legal obligation?
Explanation: A stolen laptop with unencrypted customer data is likely a reportable breach - the organization must immediately assess what data was on the device and determine applicable notification requirements under state, federal, and international laws. Answer B is correct. Laptop replacement (A) is an operational matter. A police report (C) alone is insufficient. Waiting 30 days (D) would likely violate notification deadlines.
An organization's incident response plan requires that any incident involving personal data be escalated to the privacy officer within 4 hours of identification. During an audit, the auditor finds that 6 of 10 sampled incidents involving personal data were not escalated to the privacy officer at all. The auditor should:
Explanation: A 60% failure rate in escalating personal data incidents to the privacy officer means notification obligations were likely not assessed - a significant compliance and legal risk. Answer B is correct. Resolution of incidents (A) does not substitute for proper escalation. Officer availability (C) is irrelevant if escalation did not occur. The plan's requirement is mandatory, not aspirational (D).
Under U.S. state breach notification laws, notification to affected individuals is generally required when:
Explanation: Most U.S. state breach notification laws trigger individual notification when defined categories of sensitive personal information (PII, financial data, health data) are compromised - particularly when unencrypted. Answer D is correct. Not all unauthorized access triggers notification (A). Thresholds (B) vary by state. Legal triggers, not customer service decisions (C), mandate notification.
A company's incident response plan has not been updated in three years and does not reflect the current IT infrastructure, key contacts, or regulatory requirements. The primary risk of this outdated plan is:
Explanation: An outdated IR plan leads to confusion, delays, and missed obligations during an actual incident - exactly when clarity and speed matter most. Answer B is correct. External auditors may note the gap (A) but the operational risk is more significant. Insurance premiums (C) are not automatically affected. Training (D) is unrelated.
Which of the following scenarios would trigger a SEC cybersecurity incident disclosure requirement for a publicly traded company under the SEC's 2023 cybersecurity disclosure rules?
Explanation: The SEC's 2023 cybersecurity rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining the incident is material. Answer C is correct. Disclosure is not required for all incidents (A). Materiality is broader than just customer data theft (B). The rules apply to all material incidents, not just international ones (D).
A major financial institution experiences a cybersecurity incident that disrupts trading systems for 4 hours. Under applicable financial sector regulations, which of the following reporting obligations most likely apply?
Explanation: Financial sector regulations (including the federal banking agencies' Computer-Security Incident Notification Rule) require prompt notification to primary regulators for significant cybersecurity incidents. Answer D is correct. Duration alone does not exempt incidents from reporting (A). Board notification (B) is internal governance. Law enforcement notification (C) may also be appropriate but is separate from regulatory reporting.
A company discovers a data breach involving customer financial information on a Friday evening. Under most breach notification laws (such as GDPR's 72-hour requirement), the organization's first obligation is to:
Explanation: Breach notification clocks typically start when the organization becomes aware - GDPR's 72-hour supervisory authority notification requirement does not pause for weekends or investigations. Immediate scoping and assessment is essential. Answer D is correct. Waiting until Monday (A) risks missing notification deadlines. Customer notification (B) typically follows regulatory notification. A complete investigation (C) may take far longer than notification deadlines allow.
An organization's incident response team is investigating a potential breach and discovers log files that show unauthorized access. The team should:
Explanation: Log files are critical evidence - they must be preserved in their original, unmodified state with proper chain of custody to be usable in legal proceedings or regulatory investigations. Answer D is correct. Deleting (A) or modifying (C) logs is evidence tampering. Public sharing (B) may alert attackers and compromise the investigation.
Which of the following correctly identifies the phases of a typical incident response lifecycle?
Explanation: The NIST SP 800-61 incident response lifecycle has six phases: Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post-Incident Activity. Answer C is correct. Answer A is COBIT management phases. Answer B is the NIST Cybersecurity Framework functions. Answer D is a generic process model.
During a ransomware incident, the IT team's first priority should be to:
Explanation: Containment - isolating affected systems - is the first priority to stop ransomware from spreading to additional systems. Investigation, notification, and recovery follow containment. Answer A is correct. Paying ransom (B) is a last resort. Root cause analysis (C) occurs after containment. Customer notification (D) follows assessment of data exposure.
The primary purpose of the 'eradication' phase of incident response is to:
Explanation: Eradication focuses on completely removing the attacker's presence and tools from the environment - not just stopping the immediate attack but eliminating all footholds. Answer B is correct. System restoration (A) is the recovery phase. Stakeholder notification (C) occurs during and after containment. Lessons learned (D) are post-incident activities.
An organization's incident response plan includes a 'containment strategy decision tree.' The primary purpose of this decision tool is to:
Explanation: A containment decision tree helps responders quickly determine the right containment strategy for different incident types - balancing the urgency to stop spread against the need to maintain critical operations. Answer D is correct. Regulatory routing (A), cost calculation (B), and root cause identification (C) are separate activities in the IR lifecycle.
Which of the following best describes the 'recovery' phase of incident response?
Explanation: Recovery focuses on restoring normal operations safely - rebuilding systems, restoring data from verified clean backups, and confirming functionality before re-entering production. Answer A is correct. Analyzing indicators of compromise (B) is detection and analysis. Removing malware (C) is eradication. Stakeholder communication (D) runs throughout the IR lifecycle.
An organization's incident response plan designates a Computer Security Incident Response Team (CSIRT). The CSIRT should include representatives from which functions?
Explanation: Effective incident response requires cross-functional coordination: IT handles technical response, legal manages liability and regulatory obligations, communications manages external messaging, HR addresses employee-related matters, and business units understand business impact. Answer C is correct. Technical staff alone (A) cannot manage legal, PR, or business implications. Management and legal alone (B) cannot execute technical response. External agencies (D) may be involved but do not constitute the internal CSIRT.
Which of the following best describes the purpose of a 'tabletop exercise' in incident response preparedness?
Explanation: Tabletop exercises test incident response knowledge and coordination through discussion of simulated scenarios - identifying gaps in procedures, communication, and decision-making without the risk and cost of live exercises. Answer A is correct. Full system failover (B) is a full-scale exercise. Physical security drills (C) test physical controls. Policy reviews (D) assess documentation.
Which of the following is the most important document to maintain during an incident for both operational and legal purposes?
Explanation: A detailed incident log provides the authoritative record of what happened, when, by whom, and why - essential for regulatory reporting, legal proceedings, lessons learned, and demonstrating due diligence. Answer A is correct. Backups (B) are important for recovery. Employee notification lists (C) are one element of documentation. Insurance policies (D) are business documents, not incident records.
An organization detects a breach and finds evidence that attackers had access for 45 days before detection. This period between initial compromise and detection is called:
Explanation: Dwell time measures how long an attacker operates undetected within a network - a key indicator of detection capability maturity. Shorter dwell time means faster detection and less damage. Answer C is correct. RTO (A) measures recovery speed. MTTR (B) measures response time after detection. The notification window (D) is a regulatory compliance concept.
When a breach notification is sent to affected individuals, which of the following information should typically be included?
Explanation: Breach notifications should be clear and actionable - explaining the incident, what data was affected, organizational response actions, protective steps individuals can take, and how to get help. Answer A is correct. Technical attack details (B) are not helpful to individuals and may aid further attacks. Employee names (C) are confidential. Full data inventories (D) are not required and may raise additional privacy concerns.
Which of the following is the most critical element of an effective incident response plan?
Explanation: Clarity about who does what, who decides what, and how information flows is the foundation of effective incident response - confusion about roles during an active incident wastes critical time. Answer B is correct. Asset inventories (A) support response but are not the most critical IR element. Threat actor lists (C) and MSSP contracts (D) support security programs but are not foundational to IR plan effectiveness.