220-1102 Question 621
Single answerLeaked personal files/dataA user reports that a folder containing scanned tax documents and copies of IDs was accidentally uploaded from a company laptop to a public file-sharing site. The help desk confirms the files contain personally identifiable information (PII). According to security best practices, what should the technician do FIRST?
- A
Immediately notify the organization's security team or incident response process and preserve relevant details about the exposure
- B
Delete the local copies of the files from the laptop so no additional leaks can occur
- C
Post a message to the company's internal chat asking whether anyone recognizes the public link
- D
Run a full malware scan on the laptop before reporting the issue
Show answer and explanation
Correct answer: A
Explanation
This question tests incident response in the context of leaked personal files or data, a common A+ Core 2 security topic. For exposed PII, the technician should first report the incident through the organization's established security or incident response process rather than trying ad hoc fixes. Best practices in incident handling emphasize identifying and reporting the incident, preserving evidence, limiting unnecessary disclosure, and then proceeding with containment, eradication, and recovery under organizational guidance. In practice, this often includes documenting what was exposed, where it was posted, when it was discovered, and which systems or accounts were involved. This aligns with standard security guidance such as using formal incident response procedures and proper handling of sensitive data.
- A. Correct.
Correct. When personal data or sensitive files are exposed, the first step is to follow the organization's security incident or data breach reporting process. This helps contain the exposure, ensure proper escalation, preserve evidence, and coordinate next steps such as takedown requests, legal review, and user notification if required. Preserving details such as the URL, time discovered, affected files, and account involved is important for incident handling.
- B. Incorrect.
Incorrect. Deleting local copies does not address the primary issue, which is that the files were already exposed publicly. It may also interfere with investigation or evidence collection. Containment and escalation through the proper incident process should happen first.
- C. Incorrect.
Incorrect. Broadcasting the issue in a general internal chat is not an appropriate first action and can unnecessarily spread sensitive information, including the public link. Security incidents involving PII should be handled through approved reporting channels on a need-to-know basis.
- D. Incorrect.
Incorrect. A malware scan may be useful later if the cause of the upload is unknown, but it is not the first priority once a confirmed data exposure has occurred. The immediate focus should be incident reporting, containment, and preservation of relevant evidence.