ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 161 - CS0-003 discussion

Report
Export

During an incident, analysts need to rapidly investigate by the investigation and leadership teams.

Which of the following best describes how PII should be safeguarded during an incident?

A.
Implement data encryption and close the data so only the company has access.
Answers
A.
Implement data encryption and close the data so only the company has access.
B.
Ensure permissions are limited in the investigation team and encrypt the data.
Answers
B.
Ensure permissions are limited in the investigation team and encrypt the data.
C.
Implement data encryption and create a standardized procedure for deleting data that is no longer needed.
Answers
C.
Implement data encryption and create a standardized procedure for deleting data that is no longer needed.
D.
Ensure that permissions are open only to the company.
Answers
D.
Ensure that permissions are open only to the company.
Suggested answer: B

Explanation:

The best option to safeguard PII during an incident is to ensure permissions are limited in the investigation team and encrypt the data. This is because limiting permissions reduces the risk of unauthorized access or leakage of sensitive data, and encryption protects the data from being read or modified by anyone who does not have the decryption key. Option A is not correct because closing the data may hinder the investigation process and prevent collaboration with other parties who may need access to the data. Option C is not correct because deleting data that is no longer needed may violate legal or regulatory requirements for data retention, and may also destroy potential evidence for the incident. Option D is not correct because opening permissions to the company may expose the data to more people than necessary, increasing the risk of compromise or misuse.

Reference: CompTIA CySA+ Study Guide: Exam CS0-002, 2nd Edition, Chapter 4, “Data Protection and Privacy Practices”, page 195; CompTIA CySA+ Certification Exam Objectives Version 4.0, Domain 4.0

“Compliance and Assessment”, Objective 4.1 “Given a scenario, analyze data as part of a security incident”, Sub-objective “Data encryption”, page 23

: CompTIA CySA+ Study Guide: Exam CS0-002, 2nd Edition : CompTIA CySA+ Certification Exam Objectives Version 4.0.pdf)

asked 02/10/2024
Istvan Flach
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first