CompTIA A+ Core 2 (220-1202)Operational ProceduresHard
A technician discovers that a database containing customer personally identifiable information (PII) was accidentally exposed on a public file share. Which of the following actions should the technician take FIRST?
- ANotify the appropriate incident response or security team according to company policy
- BDelete the exposed data immediately without reporting it
- CContinue working on the original support ticket and address it later
- DEncrypt the credentials used to access the file share
Show answer & explanationAnswer & explanation
Correct answer: A. Notify the appropriate incident response or security team according to company policy
Exposure of PII is a potential data breach that must be escalated immediately to the incident response or security team per organizational policy and applicable privacy regulations. Deleting evidence or delaying the report could worsen legal exposure and hinder proper investigation.
Why the other options are wrong
- B. Deleting data without reporting could destroy evidence needed for investigation and violate policy.
- C. Delaying escalation increases risk and potential regulatory non-compliance.
- D. Encrypting credentials doesn't address the already-exposed data or fulfill reporting obligations.
PII Breach Response
When personally identifiable information is exposed or compromised, technicians must immediately escalate to security/incident response teams per policy, rather than attempting to resolve it independently.
- PII breaches may have legal/regulatory reporting requirements
- Technicians should preserve evidence, not delete data
- Escalation ensures proper handling and compliance
Memory trick: See a breach? Speak up first, don't clean up first.