200-201 Question 241
Single answerYour organization’s Security Operations Center (SOC) detects unauthorized access to a file server containing sensitive customer data. A forensic investigation reveals that no data was exfiltrated or modified. Which of the following best describes the impact of this event?
- A
No impact, as no data was exfiltrated or modified.
- B
Low impact, as the unauthorized access could lead to potential future compromises.
- C
Moderate impact, because the incident involved sensitive customer data.
- D
High impact, due to the breach of customer trust and regulatory implications.
Show answer and explanation
Correct answer: B
Explanation
While no immediate harm occurred, the unauthorized access to a system containing sensitive customer data highlights a security gap. This presents a low impact because of the potential risks of future attacks or exploitation. Understanding the differences between no impact and varying levels of impact is critical for assessing the severity of cybersecurity incidents.
- A. Incorrect.
Incorrect. While no data was exfiltrated or modified, unauthorized access still indicates a security vulnerability that could have future consequences.
- B. Correct.
Correct. Unauthorized access, even without data exfiltration or modification, poses a low impact due to the potential risk of future compromises and the exposure of sensitive systems.
- C. Incorrect.
Incorrect. The impact is not moderate because there was no indication of data loss, misuse, or breach of confidentiality in this specific instance.
- D. Incorrect.
Incorrect. High impact would be applicable if customer trust was directly affected or if regulatory violations occurred due to data loss, which is not the case here.