🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A U.S. healthcare provider's multi-region serverless app on AWS had a public S3 bucket with PHI. CloudTrail shows several anonymous downloads. Public access is now blocked, credentials rotated, and evidence collection started. Policy and HIPAA both require breach disclosure, and all public messaging needs executive and legal approval. According to best practice for public-relations coordination during detection and escalation, what should the incident response team do next?

  • Escalate the incident to the organization's designated communications lead and legal counsel to develop and approve an official external statement before any public disclosure.

  • Publish a detailed breach notice on the company's public website immediately to demonstrate full transparency.

  • Delete the S3 access logs and any related evidence to minimize potential reputational damage before engaging external parties.

  • Continue internal forensic analysis for at least 48 hours before notifying regulators or customers so that complete technical details are available.

ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot