712-50 Question 264
Single answerDesign a response plan to identity theft incidencesA multinational retailer discovers that attackers used a phishing campaign against HR staff to obtain employee payroll portal credentials and exfiltrate personally identifiable information (PII), including names, addresses, national ID numbers, and bank account details for several thousand employees. The CEO asks the CISO to approve the identity-theft response plan for affected employees. Which action should be the HIGHEST priority to include in the plan to most effectively reduce harm from likely identity-theft misuse of the stolen data?
- A
Immediately disable compromised accounts, preserve forensic evidence, notify affected employees with clear protective steps, and coordinate rapid fraud monitoring/credit alert support with relevant financial institutions and service providers
- B
Delay employee notification until the full forensic investigation is complete so the organization can provide one final, comprehensive communication with confirmed root cause details
- C
Focus the response on malware eradication and password resets because identity theft is primarily a law-enforcement matter after data has already been stolen
- D
Issue a public press statement first to protect corporate reputation, then determine later whether individual employees need direct assistance
- E
Offer affected employees a one-time password reset for the payroll system and consider the matter closed unless fraudulent transactions are reported
Show answer and explanation
Correct answer: A
Explanation
For a CCISO-level response plan, the key objective is not just technical containment but minimizing business and human harm from misuse of stolen identity data. In identity-theft incidents, executive leadership should ensure the plan covers: containment of compromised access; preservation of evidence; legal, regulatory, and contractual notification requirements; prompt communication to affected individuals; coordination with HR, legal, privacy, fraud teams, payroll providers, and financial institutions; and support measures such as fraud alerts, account monitoring, or credit-protection guidance where appropriate. This reflects established breach-response and incident-management principles in sources such as NIST SP 800-61 Rev. 2 (Computer Security Incident Handling Guide), which emphasizes containment, eradication, recovery, and communication, and NIST's data breach response guidance, which stresses timely notification and harm reduction for affected individuals. The best answer is the one that combines technical response with victim protection and cross-functional coordination.
- A. Correct.
Correct. A strong identity-theft response plan must prioritize immediate containment, evidence preservation, and prompt victim-centric mitigation. In this scenario, the stolen data can be used quickly for account takeover, new-account fraud, tax fraud, and social engineering. Therefore, the plan should include disabling compromised accounts, preserving logs and artifacts for investigation, notifying affected individuals without unnecessary delay, and providing practical assistance such as fraud monitoring, credit alert/freeze guidance where applicable, and coordination with banks or payroll-related providers. This aligns with major incident-response and breach-response practices, which emphasize containment, investigation, notification, and harm reduction.
- B. Incorrect.
Incorrect. Waiting for complete forensic certainty is a common but harmful mistake in identity-theft incidents. While accuracy matters, delaying notification can increase the window in which attackers exploit PII for fraud. Best practice is to provide timely initial notice with actionable steps, then follow up as new facts emerge. The misconception here is that complete technical certainty is more important than reducing victim harm.
- C. Incorrect.
Incorrect. Malware eradication and password resets are necessary, but they are not sufficient when sensitive identity data has already been exposed. Treating identity theft as someone else's problem ignores the organization's responsibility to support impacted individuals and coordinate downstream protections. The misconception is narrowing incident response to technical recovery only, rather than managing business, legal, and human impact.
- D. Incorrect.
Incorrect. Public relations activity may be necessary, but it should not take precedence over direct support to affected individuals. A response plan for identity theft must be centered on those at risk, including timely individual communication and protective guidance. Choosing this option reflects a reputation-first rather than risk-first approach, which is inconsistent with effective executive security leadership.
- E. Incorrect.
Incorrect. Resetting passwords addresses only one abuse path and does not mitigate misuse of stolen national IDs, addresses, and bank details. Identity theft can continue long after account credentials are changed. This option underestimates the breadth and duration of potential harm and fails to include monitoring, notification, and coordination with external parties.