Question 1 of 30
Research into a recent network intrusion at a multinational e-commerce company has revealed that sensitive customer data, including names, addresses, and partial payment card information, may have been accessed. The company serves customers across the European Union and the United States. What is the most appropriate immediate course of action for the cybersecurity team to take regarding regulatory compliance?
Immediately determine the specific types of data compromised and identify which regulatory frameworks (e.g., GDPR, HIPAA, PCI-DSS) apply based on the data and affected customer locations, then initiate the appropriate notification and investigation procedures.
Issue a broad public statement acknowledging a security incident and begin a general investigation into the network intrusion, deferring specific regulatory compliance actions until the full scope of the breach is technically understood.
Prioritize the technical containment and eradication of the threat, assuming that regulatory notification can be addressed once the system is secured, as technical stability is the primary concern.
Focus on notifying only US-based customers about the potential breach, as US regulations are generally perceived as more stringent and will likely cover the incident broadly, while delaying EU-specific notifications.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free