Artificial Intelligence Governance Professional AIGP · Free Practice Question Medium
Question 12
A health research organization discovers that confidential patient data became accessible online due to an incorrectly configured cloud storage bucket. Which factor MOST accurately classifies this event as a data leak rather than a data breach?
- A Sensitive data was intentionally shared with a third-party vendor for legitimate business purposes
- B Unauthorized access was carried out by an external cybercriminal
- C The organization had strict access controls and regular audits in place
- D The exposure was unintentional and resulted from a misconfiguration rather than malicious activity
Reveal correct answer
Correct answer: D
Explanation
Data leaks are characterized by unintentional exposure due to oversight, not malice or intent to steal.A. Intentional, authorized sharing is not a data leak.
B. Deliberate unauthorized access is typically classified as a data breach.
C. Strong controls would likely have prevented the incident, but do not define leak versus breach.
D. A data leak is defined by accidental exposure due to human error or weak controls, not deliberate hacking or theft.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
