U.S. Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP CIPP-E Exam - Topic 2 Question 124 Discussion

Once an organization has conducted an internal investigation to determine the scope of a ransomware attack, what is the appropriate next step in the process?
A) Assess the risks associated with the breach and, if necessary, notify affected individuals and regulatory bodies within the relevant timeframes.
B) Notify law enforcement and consult with legal counsel to understand the implications of the breach and the notification requirements.
C) Inform all customers and the public via social media platforms to ensure rapid dissemination of relevant information.
D) Wait for law enforcement to provide guidance on notification procedures before taking any further action.

IAPP CIPP-E Exam - Topic 2 Question 124 Discussion

Actual exam question for IAPP's CIPP-E exam
Question #: 124
Topic #: 2
[All CIPP-E Questions]

Once an organization has conducted an internal investigation to determine the scope of a ransomware attack, what is the appropriate next step in the process?

Show Suggested Answer Hide Answer
Suggested Answer: A

The GDPR (General Data Protection Regulation) has strict data breach response requirements, particularly for ransomware attacks that affect personal data. The appropriate next step after an internal investigation is to assess the risks associated with the breach and notify affected parties if necessary.

Key GDPR Breach Response Steps (Article 33 & 34):

Assess the risks to personal data

If the breach poses a risk to individuals' rights and freedoms, the supervisory authority (DPA) must be notified within 72 hours.

If there is a high risk, affected individuals must also be informed without undue delay.

Why Answer Choice A is Correct

Risk assessment is a critical first step after an internal investigation.

If the breach meets the risk threshold, notification to authorities and individuals is required under GDPR.

Why Other Answer Choices Are Incorrect:

B (Notify Law Enforcement First): While law enforcement may be involved, GDPR does not mandate consulting law enforcement before conducting a risk assessment or notifying individuals.

C (Informing the Public Immediately): Public disclosure via social media is not a GDPR requirement. Affected individuals and DPAs should be formally notified first.

D (Waiting for Law Enforcement): GDPR does not allow waiting for law enforcement before fulfilling notification obligations. Controllers must act within 72 hours.

Conclusion: The correct next step after an internal investigation is to assess the risks and, if necessary, notify affected individuals and regulatory bodies as required under GDPR Articles 33 and 34.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel