Question 1 of 30
Risk assessment procedures indicate a potential unauthorized access to a customer database containing personally identifiable information (PII). The alert is high-priority, but the exact scope and impact are not yet fully determined. As the Chief Information Security Officer (CISO), what is the most appropriate immediate course of action?
Immediately activate the incident response plan, isolate affected systems to prevent further compromise, and begin a preliminary assessment to determine the scope and nature of the potential breach.
Issue a public statement acknowledging a potential data breach to maintain transparency with customers and stakeholders.
Halt all investigative activities until a complete forensic analysis can be performed to definitively confirm the breach and its full extent.
Proceed with notifying all affected customers immediately based on the initial alert, without further verification of the data involved.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free