200-201 exam dumps

200-201 practice question 394 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 394

Select 3

A healthcare organization has experienced a ransomware attack where sensitive patient information, including medical records, was encrypted and an attacker threatened to release it unless a ransom was paid. Which of the following actions would align with protecting PHI (Protected Health Information) during and after the incident?

  1. A

    Report the breach to affected individuals and relevant authorities as required by HIPAA regulations.

  2. B

    Pay the ransom immediately to prevent PHI from being leaked.

  3. C

    Initiate a forensic investigation to determine the scope of the breach and ensure no further unauthorized access.

  4. D

    Strengthen security measures and provide employee training to prevent future breaches involving PHI.

  5. E

    Delete all encrypted data immediately to avoid further exposure.

Show answer and explanation

Correct answers: A, C, D

Explanation

PHI is highly sensitive information, and its protection is governed by HIPAA regulations in the United States. During a ransomware attack, it is crucial to address the incident in a manner that prioritizes compliance, data recovery, and future prevention. Reporting the breach, conducting a forensic investigation, and strengthening security measures align with these objectives, while paying the ransom or deleting data without a proper plan can exacerbate the issue.

  • A. Correct.

    Reporting the breach is a legal requirement under HIPAA for incidents involving PHI. This ensures transparency and compliance with regulations.

  • B. Incorrect.

    Paying the ransom is not recommended as it does not guarantee the attacker will honor their promise, and it could incentivize further attacks.

  • C. Correct.

    Conducting a forensic investigation helps identify the extent of the breach, potential vulnerabilities, and ensures proper remediation steps are taken.

  • D. Correct.

    Strengthening security measures and providing employee training can help mitigate the risk of future breaches and ensure better handling of PHI.

  • E. Incorrect.

    Deleting encrypted data without proper investigation might result in loss of critical information and evidence required for recovery and compliance.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam