Artificial Intelligence Governance Professional AIGP · Free Practice Question Medium

Question 12

A health research organization discovers that confidential patient data became accessible online due to an incorrectly configured cloud storage bucket. Which factor MOST accurately classifies this event as a data leak rather than a data breach?
  • A Sensitive data was intentionally shared with a third-party vendor for legitimate business purposes
  • B Unauthorized access was carried out by an external cybercriminal
  • C The organization had strict access controls and regular audits in place
  • D The exposure was unintentional and resulted from a misconfiguration rather than malicious activity
Reveal correct answer

Correct answer: D

Explanation

Data leaks are characterized by unintentional exposure due to oversight, not malice or intent to steal.

A. Intentional, authorized sharing is not a data leak.

B. Deliberate unauthorized access is typically classified as a data breach.

C. Strong controls would likely have prevented the incident, but do not define leak versus breach.

D. A data leak is defined by accidental exposure due to human error or weak controls, not deliberate hacking or theft.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need