Certified In Cybersecurity CC · Free Practice Question Medium
Question 41
As the Chief Information Security Officer (CISO) of ThorTeaches.com, Edward has been informed that the company's networks have been breached and sensitive data has been stolen. He suspects that the breach may have been caused by an insider threat. How should he proceed?
- A Conduct an internal investigation to identify the source of the breach and take disciplinary action against any employees found to be responsible.
- B Issue a statement to the media acknowledging the breach and promising to take measures to prevent future breaches.
- C All of these.
- D Implement additional security measures, such as two-factor authentication, to prevent future breaches.
Reveal correct answer
Correct answer: A
Explanation
The correct answer: Conduct an internal investigation to identify the source of the breach and take disciplinary action against any employees found to be responsible. An internal investigation should be the first step when there is a suspicion of an insider threat. This is because it helps in identifying the source of the breach, and determining whether the breach was indeed caused by an internal actor or not. The investigation will include a comprehensive review of access logs, communication records, and other relevant data, which will help in identifying any suspicious activities or anomalies. If an employee is found to be responsible, disciplinary action will be required according to company policy and local laws. This step is crucial to understanding the scope, impact, and root cause of the breach, and to determine the next steps. The incorrect answers: Issue a statement to the media acknowledging the breach and promising to take measures to prevent future breaches. Transparency is crucial in the event of a breach, prematurely issuing a statement to the media can be harmful. Before making any public announcements, it's essential to understand the full scope and impact of the breach through a thorough internal investigation. Releasing a statement without complete information can lead to misinformation, panic, and potential legal complications. Implement additional security measures, such as two-factor authentication, to prevent future breaches. Implementing additional security measures like two-factor authentication is an important step in strengthening the overall security posture of the company, it's not the immediate step to take when a breach has occurred, particularly if an insider threat is suspected. The priority should be on identifying the root cause of the breach, mitigating its effects, and then updating security measures based on the findings of the investigation. All of these. Each of the actions mentioned may be appropriate at certain stages of dealing with a security breach, they are not all immediate reactions or carried out at the same time. The first step is always to conduct an internal investigation. The findings from this investigation would then guide the implementation of security measures and the content and timing of any public statements.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
