Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IAPP CIPP-E Exam - Topic 2 Question 124 Discussion

Once an organization has conducted an internal investigation to determine the scope of a ransomware attack, what is the appropriate next step in the process?
A) Assess the risks associated with the breach and, if necessary, notify affected individuals and regulatory bodies within the relevant timeframes.
B) Notify law enforcement and consult with legal counsel to understand the implications of the breach and the notification requirements.
C) Inform all customers and the public via social media platforms to ensure rapid dissemination of relevant information.
D) Wait for law enforcement to provide guidance on notification procedures before taking any further action.

IAPP CIPP-E Exam - Topic 2 Question 124 Discussion

Actual exam question for IAPP's CIPP-E exam
Question #: 124
Topic #: 2
[All CIPP-E Questions]

Once an organization has conducted an internal investigation to determine the scope of a ransomware attack, what is the appropriate next step in the process?

Show Suggested Answer Hide Answer
Suggested Answer: A

The GDPR (General Data Protection Regulation) has strict data breach response requirements, particularly for ransomware attacks that affect personal data. The appropriate next step after an internal investigation is to assess the risks associated with the breach and notify affected parties if necessary.

Key GDPR Breach Response Steps (Article 33 & 34):

Assess the risks to personal data

If the breach poses a risk to individuals' rights and freedoms, the supervisory authority (DPA) must be notified within 72 hours.

If there is a high risk, affected individuals must also be informed without undue delay.

Why Answer Choice A is Correct

Risk assessment is a critical first step after an internal investigation.

If the breach meets the risk threshold, notification to authorities and individuals is required under GDPR.

Why Other Answer Choices Are Incorrect:

B (Notify Law Enforcement First): While law enforcement may be involved, GDPR does not mandate consulting law enforcement before conducting a risk assessment or notifying individuals.

C (Informing the Public Immediately): Public disclosure via social media is not a GDPR requirement. Affected individuals and DPAs should be formally notified first.

D (Waiting for Law Enforcement): GDPR does not allow waiting for law enforcement before fulfilling notification obligations. Controllers must act within 72 hours.

Conclusion: The correct next step after an internal investigation is to assess the risks and, if necessary, notify affected individuals and regulatory bodies as required under GDPR Articles 33 and 34.


Contribute your Thoughts:

0/2000 characters
Davida
1 day ago
Totally agree with B, legal advice is crucial here.
upvoted 0 times
...
Man
6 days ago
A is also important, gotta assess the risks first!
upvoted 0 times
...
Merissa
11 days ago
Wait, isn't it risky to notify everyone right away?
upvoted 0 times
...
Leatha
17 days ago
Definitely B, law enforcement needs to be in the loop.
upvoted 0 times
...
Lilli
22 days ago
I remember a case study where waiting for law enforcement led to complications, so I don't think option D is a good idea. We need to act quickly, but I’m not sure which option is best.
upvoted 0 times
...
Rupert
27 days ago
I recall discussing the importance of timely notifications in class, so I think option A makes sense. But I wonder if we should prioritize notifying law enforcement first?
upvoted 0 times
...
Rosalia
1 month ago
I'm not entirely sure, but I feel like assessing risks and notifying affected individuals is crucial too. It seems like a logical step after figuring out the scope of the attack.
upvoted 0 times
...
Stephen
1 month ago
I think the next step should be to notify law enforcement and consult with legal counsel. I remember a practice question that emphasized the importance of legal guidance in these situations.
upvoted 0 times
...

Save Cancel