Question 1 of 30
Research into a recent cybersecurity incident at a financial services firm indicates a sophisticated ransomware attack that encrypted critical customer data. The firm\'s incident response team has confirmed the attack and is working on containment and recovery. However, they are unsure about the immediate reporting obligations to the relevant financial regulatory authorities and data protection agencies. Which of the following actions represents the most appropriate and compliant initial response?
Immediately engage legal counsel and the designated compliance officer to assess regulatory reporting requirements and initiate necessary notifications while continuing containment and recovery efforts.
Prioritize full technical containment and system restoration before considering any external reporting to regulatory bodies.
Attempt to resolve the incident internally and only report if the extent of the data compromise becomes undeniably significant and unavoidable.
Focus solely on eradicating the ransomware and recovering data, assuming that regulatory notification can be handled after all operational disruptions have ceased.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free