Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB Exam GDPR Topic 1 Question 4 Discussion

Actual exam question for PECB's GDPR exam
Question #: 4
Topic #: 1
[All GDPR Questions]

An organization suffered a personal data breach. The attackers gained access to their database through a user account that had unlimited access to dat

a. What should the DPO advise the organization to do in order to prevent the recurrence of similar scenarios?

Show Suggested Answer Hide Answer
Suggested Answer: A

GDPR Article 32(1)(b) emphasizes implementing access controls to ensure data security. Reviewing and restricting account permissions using the principle of least privilege (PoLP) helps prevent unauthorized access. Shared accounts (option C) increase security risks, and using cloud computing (option B) does not directly address access control vulnerabilities.


Contribute your Thoughts:

Alexia
2 months ago
A is the correct answer, no doubt. But I bet the IT team is still going to try and convince the DPO to go with C. 'It's more cost-effective!'
upvoted 0 times
Evangelina
1 months ago
DPO: Option A is the correct choice to prevent similar scenarios.
upvoted 0 times
...
Cherry
2 months ago
IT team: We should go with option C, it's more cost-effective.
upvoted 0 times
...
...
Brinda
2 months ago
C? Seriously? Shared accounts are a security nightmare waiting to happen. A is the way to go.
upvoted 0 times
Tequila
25 days ago
B) Use cloud computing services to mitigate the risk of personal data breaches
upvoted 0 times
...
Zona
30 days ago
C? Seriously? Shared accounts are a security nightmare waiting to happen. A is the way to go.
upvoted 0 times
...
Horace
1 months ago
A) Review if the access control system allows the creation, approval, review, and deletion of user accounts
upvoted 0 times
...
Dudley
1 months ago
B) Use cloud computing services to mitigate the risk of personal data breaches
upvoted 0 times
...
Rodolfo
1 months ago
C? Seriously? Shared accounts are a security nightmare waiting to happen. A is the way to go.
upvoted 0 times
...
Nydia
2 months ago
A) Review if the access control system allows the creation, approval, review, and deletion of user accounts
upvoted 0 times
...
...
Lynelle
3 months ago
Creating and using shared accounts for several users might not be a good idea as it can lead to security vulnerabilities.
upvoted 0 times
...
Lenita
3 months ago
I believe using cloud computing services could also help mitigate the risk of personal data breaches.
upvoted 0 times
...
Barbra
3 months ago
I can already hear the DPO sighing heavily at the mere suggestion of C. 'Do you want to get hacked again? No? Then we're doing A.'
upvoted 0 times
Raylene
2 months ago
I can already hear the DPO sighing heavily at the mere suggestion of C. 'Do you want to get hacked again? No? Then we're doing A.'
upvoted 0 times
...
Penney
2 months ago
C) Create and use shared accounts for several users in order to minimize the number of user accounts
upvoted 0 times
...
Ashlyn
2 months ago
B) Use cloud computing services to mitigate the risk of personal data breaches
upvoted 0 times
...
Maryln
2 months ago
A) Review if the access control system allows the creation, approval, review, and deletion of user accounts
upvoted 0 times
...
...
Annamaria
3 months ago
I agree with Ivette. It's important to ensure user accounts are created, approved, reviewed, and deleted properly.
upvoted 0 times
...
Ivette
3 months ago
I think the DPO should advise the organization to review the access control system.
upvoted 0 times
...
Ruth
3 months ago
A seems like the obvious choice here. Reviewing the access control system is key to preventing similar breaches.
upvoted 0 times
Adelle
2 months ago
I agree, reviewing the access control system is crucial in preventing breaches.
upvoted 0 times
...
Candida
2 months ago
C) Create and use shared accounts for several users in order to minimize the number of user accounts
upvoted 0 times
...
Micaela
2 months ago
B) Use cloud computing services to mitigate the risk of personal data breaches
upvoted 0 times
...
Wynell
2 months ago
A) Review if the access control system allows the creation, approval, review, and deletion of user accounts
upvoted 0 times
...
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77