200-201 Question 396
Select 3A cybersecurity analyst at your organization discovers that an employee has been using company resources to download and share proprietary designs and source code with an external competitor. Which of the following steps should the analyst take to address this intellectual property (IP) breach?
- A
Report the incident to the organization's legal and HR departments immediately.
- B
Notify the competitor involved to request the return of the shared intellectual property.
- C
Preserve all relevant evidence, including logs, emails, and file transfers, for investigation.
- D
Terminate the employee's access to all systems without prior notice or investigation.
- E
Evaluate and implement additional security controls to prevent future intellectual property theft.
Show answer and explanation
Correct answers: A, C, E
Explanation
Intellectual property theft is a serious incident that requires a structured response. Reporting the breach to appropriate internal departments ensures that legal and disciplinary measures are taken correctly. Preserving evidence is crucial for investigations and legal proceedings. Finally, implementing additional security controls reduces the risk of future breaches. Actions such as notifying external entities or immediately terminating access without proper investigation can cause more harm than good and should be avoided.
- A. Correct.
Reporting the incident to the organization's legal and HR departments is critical for ensuring a proper and lawful response to the theft of intellectual property.
- B. Incorrect.
Notifying the competitor directly is inappropriate and could compromise the investigation. Such actions should only be handled by legal teams if necessary.
- C. Correct.
Preserving evidence is essential for investigation and potential legal action. It ensures the organization has a clear record of what occurred.
- D. Incorrect.
Immediately terminating the employee's access without proper investigation could lead to legal and operational issues. Access should only be restricted after due diligence.
- E. Correct.
Evaluating and implementing additional security measures helps to prevent future incidents and strengthens the organization's overall cyber defenses.