ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A U.S. healthcare provider's multi-region serverless app on AWS had a public S3 bucket with PHI. CloudTrail shows several anonymous downloads. Public access is now blocked, credentials rotated, and evidence collection started. Policy and HIPAA both require breach disclosure, and all public messaging needs executive and legal approval. According to best practice for public-relations coordination during detection and escalation, what should the incident response team do next?
Escalate the incident to the organization's designated communications lead and legal counsel to develop and approve an official external statement before any public disclosure.
Publish a detailed breach notice on the company's public website immediately to demonstrate full transparency.
Delete the S3 access logs and any related evidence to minimize potential reputational damage before engaging external parties.
Continue internal forensic analysis for at least 48 hours before notifying regulators or customers so that complete technical details are available.
Industry guidance such as NIST SP 800-61 states that, once an incident is confirmed, the incident response team should immediately coordinate with the organization's communications or public-affairs staff-working alongside legal counsel-before any external disclosure. This ensures that statements are accurate, consistent, and legally compliant. Publishing details unilaterally, deleting evidence, or waiting days before notifying regulators violates both HIPAA requirements and incident-response best practice.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-61?
Open an interactive chat with Bash
What is considered PHI under HIPAA?
Open an interactive chat with Bash
Why is it important to involve legal counsel during a data breach response?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .