ExamGecko
Home Home / IAPP / CIPM
Question list
Search
Search

List of questions

Search

Related questions











Question 140 - CIPM discussion

Report
Export

A systems audit uncovered a shared drive folder containing sensitive employee data with no access controls and therefore was available for all employees to view. What is the first step to mitigate further risks?

A.

Notify all employees whose information was contained in the file.

Answers
A.

Notify all employees whose information was contained in the file.

B.

Check access logs to see who accessed the folder.

Answers
B.

Check access logs to see who accessed the folder.

C.

Notify legal counsel of a privacy incident.

Answers
C.

Notify legal counsel of a privacy incident.

D.

Restrict access to the folder.

Answers
D.

Restrict access to the folder.

Suggested answer: D

Explanation:

The first step to mitigate further risks when a systems audit uncovers a shared drive folder containing sensitive employee data with no access controls is to restrict access to the folder. This can be done by implementing appropriate access controls, such as user authentication, role-based access, and permissions, to ensure that only authorized individuals can view and access the sensitive data.

https://www.sans.org/cyber-security-summit/archives/file/summit-archive-1492158151.pdf

https://www.itgovernance.co.uk/blog/5-reasons-why-employees-dont-report-data-breaches/

https://www.ncsc.gov.uk/guidance/report-cyber-incident

asked 22/11/2024
Bonginhlanhla Mtshali
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first