All questions
Question 1
A healthcare organization experiences a breach of protected health information (PHI). Under HIPAA's Breach Notification Rule, the organization must notify affected individuals within:
- 24 hours of discovering the breach.
- 30 days of discovering the breach.
- 60 days of discovering the breach. (correct answer)
- 90 days of completing the forensic investigation.
Explanation: HIPAA's Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovering the breach. Answer C is correct. 24 hours (A) is not the HIPAA requirement. 30 days (B) is shorter than required but may satisfy the rule if completed. 90 days post-investigation (D) exceeds the discovery-based 60-day clock.
Question 2
A company discovers that an employee's laptop containing unencrypted customer data was stolen. Which of the following is the organization's most immediate legal obligation?
- Immediately replace the stolen laptop with a new device.
- Assess the scope of the data breach and determine applicable breach notification obligations based on the type of data, jurisdiction, and number of affected individuals. (correct answer)
- File a police report about the laptop theft and take no further action pending the investigation.
- Wait 30 days to determine whether the data has been misused before making any notifications.
Explanation: A stolen laptop with unencrypted customer data is likely a reportable breach - the organization must immediately assess what data was on the device and determine applicable notification requirements under state, federal, and international laws. Answer B is correct. Laptop replacement (A) is an operational matter. A police report (C) alone is insufficient. Waiting 30 days (D) would likely violate notification deadlines.
Question 3
An organization's incident response plan requires that any incident involving personal data be escalated to the privacy officer within 4 hours of identification. During an audit, the auditor finds that 6 of 10 sampled incidents involving personal data were not escalated to the privacy officer at all. The auditor should:
- Accept this since the incidents were ultimately resolved.
- Report this as a significant finding - the escalation control did not operate as designed, creating risk that breach notification obligations were not assessed or triggered for multiple incidents. (correct answer)
- Accept this if the privacy officer was available during the incidents.
- Accept this since the 4-hour requirement is aspirational, not mandatory.
Explanation: A 60% failure rate in escalating personal data incidents to the privacy officer means notification obligations were likely not assessed - a significant compliance and legal risk. Answer B is correct. Resolution of incidents (A) does not substitute for proper escalation. Officer availability (C) is irrelevant if escalation did not occur. The plan's requirement is mandatory, not aspirational (D).
Question 4
Under U.S. state breach notification laws, notification to affected individuals is generally required when:
- Any data is accessed by an unauthorized party, regardless of the type of data involved.
- The breach involves more than 500 individuals.
- The organization determines that customers should be informed as a matter of good customer service.
- A breach involves specific categories of sensitive personal information (such as SSNs, financial account numbers, or medical information) and the data was not encrypted or otherwise protected. (correct answer)
Explanation: Most U.S. state breach notification laws trigger individual notification when defined categories of sensitive personal information (PII, financial data, health data) are compromised - particularly when unencrypted. Answer D is correct. Not all unauthorized access triggers notification (A). Thresholds (B) vary by state. Legal triggers, not customer service decisions (C), mandate notification.
Question 5
A company's incident response plan has not been updated in three years and does not reflect the current IT infrastructure, key contacts, or regulatory requirements. The primary risk of this outdated plan is:
- The plan will be rejected by external auditors during the annual audit.
- During an actual incident, the team will follow incorrect procedures, contact wrong personnel, and miss regulatory obligations - increasing incident impact and legal exposure. (correct answer)
- The company's cyber insurance premium will automatically increase.
- Employees will not complete required security training on time.
Explanation: An outdated IR plan leads to confusion, delays, and missed obligations during an actual incident - exactly when clarity and speed matter most. Answer B is correct. External auditors may note the gap (A) but the operational risk is more significant. Insurance premiums (C) are not automatically affected. Training (D) is unrelated.
Question 6
Which of the following scenarios would trigger a SEC cybersecurity incident disclosure requirement for a publicly traded company under the SEC's 2023 cybersecurity disclosure rules?
- Any cybersecurity incident regardless of significance.
- Only incidents that result in confirmed theft of customer financial data.
- A cybersecurity incident that the company determines is material - requiring disclosure within four business days on Form 8-K. (correct answer)
- Incidents affecting systems outside the United States only.
Explanation: The SEC's 2023 cybersecurity rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of determining the incident is material. Answer C is correct. Disclosure is not required for all incidents (A). Materiality is broader than just customer data theft (B). The rules apply to all material incidents, not just international ones (D).
Question 7
A major financial institution experiences a cybersecurity incident that disrupts trading systems for 4 hours. Under applicable financial sector regulations, which of the following reporting obligations most likely apply?
- No reporting is required since the systems were restored within the same business day.
- The institution must notify only its internal board of directors.
- The institution must file a report with law enforcement within 24 hours.
- The institution must notify its primary financial regulator (e.g., OCC, Federal Reserve, FDIC) within the timeframes specified by applicable regulations, which may be as short as 36-72 hours for significant operational disruptions. (correct answer)
Explanation: Financial sector regulations (including the federal banking agencies' Computer-Security Incident Notification Rule) require prompt notification to primary regulators for significant cybersecurity incidents. Answer D is correct. Duration alone does not exempt incidents from reporting (A). Board notification (B) is internal governance. Law enforcement notification (C) may also be appropriate but is separate from regulatory reporting.
Question 8
A company discovers a data breach involving customer financial information on a Friday evening. Under most breach notification laws (such as GDPR's 72-hour requirement), the organization's first obligation is to:
- Wait until Monday to begin the notification process to ensure management is available.
- Notify all affected customers immediately by email before notifying regulators.
- Conduct a complete forensic investigation before making any notifications.
- Begin assessing the scope and nature of the breach immediately, as regulatory notification timelines start from when the organization becomes aware of the breach. (correct answer)
Explanation: Breach notification clocks typically start when the organization becomes aware - GDPR's 72-hour supervisory authority notification requirement does not pause for weekends or investigations. Immediate scoping and assessment is essential. Answer D is correct. Waiting until Monday (A) risks missing notification deadlines. Customer notification (B) typically follows regulatory notification. A complete investigation (C) may take far longer than notification deadlines allow.
Question 9
An organization's incident response team is investigating a potential breach and discovers log files that show unauthorized access. The team should:
- Immediately delete the logs to prevent the attacker from knowing they were detected.
- Share the logs publicly on social media to warn the security community.
- Modify the logs to add additional context before preserving them.
- Preserve the logs in their original state, create verified forensic copies, and maintain chain of custody documentation to ensure their integrity for investigation and potential legal proceedings. (correct answer)
Explanation: Log files are critical evidence - they must be preserved in their original, unmodified state with proper chain of custody to be usable in legal proceedings or regulatory investigations. Answer D is correct. Deleting (A) or modifying (C) logs is evidence tampering. Public sharing (B) may alert attackers and compromise the investigation.
Question 10
Which of the following correctly identifies the phases of a typical incident response lifecycle?
- Plan, Build, Run, Monitor
- Identify, Protect, Detect, Respond, Recover
- Preparation, Detection and Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (correct answer)
- Assess, Remediate, Test, Deploy
Explanation: The NIST SP 800-61 incident response lifecycle has six phases: Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post-Incident Activity. Answer C is correct. Answer A is COBIT management phases. Answer B is the NIST Cybersecurity Framework functions. Answer D is a generic process model.
Question 11
During a ransomware incident, the IT team's first priority should be to:
- Contain the attack by isolating infected systems from the network to prevent further spread before beginning investigation or recovery. (correct answer)
- Immediately pay the ransom to restore access to critical systems as quickly as possible.
- Conduct a full root cause analysis to determine how the ransomware entered the network.
- Notify all customers that their data may have been compromised.
Explanation: Containment - isolating affected systems - is the first priority to stop ransomware from spreading to additional systems. Investigation, notification, and recovery follow containment. Answer A is correct. Paying ransom (B) is a last resort. Root cause analysis (C) occurs after containment. Customer notification (D) follows assessment of data exposure.
Question 12
The primary purpose of the 'eradication' phase of incident response is to:
- Restore affected systems from clean backups to resume normal operations.
- Remove the root cause of the incident - including malware, compromised accounts, and attacker persistence mechanisms - from the affected environment. (correct answer)
- Notify stakeholders and regulatory authorities about the incident.
- Document lessons learned and improve defenses based on the incident.
Explanation: Eradication focuses on completely removing the attacker's presence and tools from the environment - not just stopping the immediate attack but eliminating all footholds. Answer B is correct. System restoration (A) is the recovery phase. Stakeholder notification (C) occurs during and after containment. Lessons learned (D) are post-incident activities.
Question 13
An organization's incident response plan includes a 'containment strategy decision tree.' The primary purpose of this decision tool is to:
- Determine which regulatory authority must be notified first.
- Calculate the financial cost of the incident for insurance purposes.
- Identify the root cause of the incident before any action is taken.
- Guide responders in selecting the appropriate containment approach based on the type and severity of the incident, balancing speed of containment against operational impact. (correct answer)
Explanation: A containment decision tree helps responders quickly determine the right containment strategy for different incident types - balancing the urgency to stop spread against the need to maintain critical operations. Answer D is correct. Regulatory routing (A), cost calculation (B), and root cause identification (C) are separate activities in the IR lifecycle.
Question 14
Which of the following best describes the 'recovery' phase of incident response?
- Restoring affected systems to normal operation - including system rebuilding, data restoration from clean backups, and validation that systems are functioning correctly before returning them to production. (correct answer)
- Identifying and analyzing indicators of compromise to understand the attack.
- Removing malware and attacker persistence mechanisms from affected systems.
- Communicating with stakeholders about the incident's impact and resolution timeline.
Explanation: Recovery focuses on restoring normal operations safely - rebuilding systems, restoring data from verified clean backups, and confirming functionality before re-entering production. Answer A is correct. Analyzing indicators of compromise (B) is detection and analysis. Removing malware (C) is eradication. Stakeholder communication (D) runs throughout the IR lifecycle.
Question 15
An organization's incident response plan designates a Computer Security Incident Response Team (CSIRT). The CSIRT should include representatives from which functions?
- Only IT security staff who have technical knowledge of the systems involved.
- Only senior management and legal counsel.
- IT security, IT operations, legal, communications/PR, HR, and relevant business units - reflecting the cross-functional nature of incident response. (correct answer)
- External law enforcement and regulatory agencies only.
Explanation: Effective incident response requires cross-functional coordination: IT handles technical response, legal manages liability and regulatory obligations, communications manages external messaging, HR addresses employee-related matters, and business units understand business impact. Answer C is correct. Technical staff alone (A) cannot manage legal, PR, or business implications. Management and legal alone (B) cannot execute technical response. External agencies (D) may be involved but do not constitute the internal CSIRT.
Question 16
Which of the following best describes the purpose of a 'tabletop exercise' in incident response preparedness?
- A discussion-based exercise where team members walk through a simulated incident scenario to test their understanding of roles, procedures, and decision-making without activating actual systems. (correct answer)
- A live technical exercise that activates the disaster recovery site to test full system failover.
- A physical security drill simulating unauthorized access to the data center.
- An annual review of the incident response policy document by IT management.
Explanation: Tabletop exercises test incident response knowledge and coordination through discussion of simulated scenarios - identifying gaps in procedures, communication, and decision-making without the risk and cost of live exercises. Answer A is correct. Full system failover (B) is a full-scale exercise. Physical security drills (C) test physical controls. Policy reviews (D) assess documentation.
Question 17
Which of the following is the most important document to maintain during an incident for both operational and legal purposes?
- A detailed incident log recording all actions taken, decisions made, timestamps, personnel involved, and evidence collected throughout the response. (correct answer)
- A complete backup of all affected systems made at the start of the incident.
- A list of all employees who were notified about the incident.
- A copy of the organization's cyber insurance policy.
Explanation: A detailed incident log provides the authoritative record of what happened, when, by whom, and why - essential for regulatory reporting, legal proceedings, lessons learned, and demonstrating due diligence. Answer A is correct. Backups (B) are important for recovery. Employee notification lists (C) are one element of documentation. Insurance policies (D) are business documents, not incident records.
Question 18
An organization detects a breach and finds evidence that attackers had access for 45 days before detection. This period between initial compromise and detection is called:
- The recovery time objective (RTO).
- The mean time to respond (MTTR).
- Dwell time - the period an attacker remains undetected within a compromised environment. (correct answer)
- The breach notification window.
Explanation: Dwell time measures how long an attacker operates undetected within a network - a key indicator of detection capability maturity. Shorter dwell time means faster detection and less damage. Answer C is correct. RTO (A) measures recovery speed. MTTR (B) measures response time after detection. The notification window (D) is a regulatory compliance concept.
Question 19
When a breach notification is sent to affected individuals, which of the following information should typically be included?
- A description of what happened, the types of information involved, what the organization is doing in response, steps individuals can take to protect themselves, and contact information for further assistance. (correct answer)
- The full technical details of the attack methodology and vulnerabilities exploited.
- The names of all employees involved in the incident response.
- A complete list of all data the organization holds about the individual.
Explanation: Breach notifications should be clear and actionable - explaining the incident, what data was affected, organizational response actions, protective steps individuals can take, and how to get help. Answer A is correct. Technical attack details (B) are not helpful to individuals and may aid further attacks. Employee names (C) are confidential. Full data inventories (D) are not required and may raise additional privacy concerns.
Question 20
Which of the following is the most critical element of an effective incident response plan?
- A detailed inventory of all IT assets and their configurations.
- Clearly defined roles and responsibilities, escalation paths, decision authorities, and communication protocols - ensuring every team member knows their role before an incident occurs. (correct answer)
- A comprehensive list of all known threat actors targeting the industry.
- A contract with a managed security service provider for 24/7 monitoring.
Explanation: Clarity about who does what, who decides what, and how information flows is the foundation of effective incident response - confusion about roles during an active incident wastes critical time. Answer B is correct. Asset inventories (A) support response but are not the most critical IR element. Threat actor lists (C) and MSSP contracts (D) support security programs but are not foundational to IR plan effectiveness.