Question 1 of 30
Compliance review shows that a financial services firm experienced a data breach affecting customer personally identifiable information. The incident response team immediately took systems offline to prevent further data loss. However, the review highlights a lack of concurrent forensic imaging and a delay in notifying the relevant data protection authority. Which of the following actions best represents a compliant and effective incident response strategy in this scenario?
Immediately initiate forensic imaging of affected systems to preserve evidence, conduct a thorough analysis to determine the scope and impact of the breach, and then proceed with regulatory notification and customer communication within the legally mandated timeframes.
Focus solely on restoring affected systems to operational status as quickly as possible to minimize business disruption, and address forensic analysis and regulatory reporting only after normal operations have resumed.
Proceed with regulatory notification and customer communication based on initial assumptions about the breach, and conduct forensic analysis and evidence preservation only if specifically requested by the regulatory authority.
Prioritize the complete eradication of the suspected threat from all systems before initiating any forensic investigation or regulatory notification, to ensure the environment is secure before further steps are taken.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free