100-160 exam dumps

100-160 practice question 248 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 248

Select 3

A company handling sensitive customer data experiences a cybersecurity incident involving unauthorized access to its systems. As part of the incident response process, the cybersecurity team must ensure compliance with relevant frameworks like GDPR and HIPAA. Which actions must be taken to adhere to compliance frameworks during incident handling?

  1. A

    Notify affected customers and regulatory bodies within the required timeframes defined by the frameworks.

  2. B

    Document the incident response process and retain records for an appropriate duration.

  3. C

    Ignore compliance requirements during the incident response to focus on resolving the issue quickly.

  4. D

    Assess whether the incident involves protected data and determine the impact based on the framework's requirements.

  5. E

    Restrict sharing incident details with external stakeholders, including regulators, to protect company reputation.

Show answer and explanation

Correct answers: A, B, D

Explanation

Compliance frameworks like GDPR and HIPAA significantly influence incident handling processes by requiring timely notification, thorough documentation, and assessment of impacted data to ensure proper response. Ignoring or failing to adhere to these requirements can result in severe penalties and harm the organization's reputation.

  • A. Correct.

    Compliance frameworks like GDPR and HIPAA mandate timely notification to affected parties and authorities. Ignoring these requirements could result in significant penalties.

  • B. Correct.

    Documenting the incident response is a critical part of compliance frameworks, as it ensures accountability and supports audits or investigations.

  • C. Incorrect.

    Ignoring compliance requirements is inappropriate and can lead to violations, fines, and reputational damage. Frameworks require organizations to balance incident resolution with compliance obligations.

  • D. Correct.

    Assessing the type of data involved and the potential impact is essential for aligning the response with framework-specific requirements like GDPR's data breach guidelines.

  • E. Incorrect.

    While confidentiality is important, withholding details from regulators is a violation of most compliance frameworks. Transparency is typically required.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam