An incident in which customer nonpublic personal information is accessed or exposed without authorization. Firms must escalate, investigate, and provide adequate notice to affected customers describing the nature of the exposure, not a vague generic statement.
Practice questions using Data Breach
Original questions written against the published FINRA and NASAA exam content outlines — not actual exam questions. Every choice is explained.
After a data breach exposing customer Social Security numbers, a firm sends affected customers a brief notice stating only that "a technical issue occurred" without describing what information was involved or what steps the customer might consider taking. A principal reviewing the notice is asked whether it is adequate. What is the concern?
A.There is no concern, since any notice mentioning that an incident occurred satisfies the firm's obligation regardless of its level of detail.Wrong. This dismisses the substantive-adequacy requirement for breach notification content.
B.A breach notification should meaningfully inform affected customers of what happened, including the type of information involved, so that they can understand the situation and consider protective steps, rather than using vague language that does not actually convey the nature of the incident.Correct. The notification should substantively convey the nature of the incident and the information involved.
C.The concern is that the notice was sent too quickly, before the firm had completed its full technical investigation of the breach.Wrong. This misidentifies the issue as timing rather than the substantive vagueness of the notice's content.
D.The concern applies only if fewer than a certain number of customers were affected; large-scale breaches have no content requirements for customer notices.Wrong. This invents a size-based exemption that does not exist.
Why: A breach notification should meaningfully inform affected customers of what happened, including the type of information involved, so that they can understand the situation and consider protective steps, rather than using vague language that does not actually convey the nature of the incident.
A firm experiences a data breach exposing customer account numbers and Social Security numbers. Several weeks pass before the incident is escalated to compliance because the IT department was still investigating the root cause. What is the concern with this sequence of events?
A.None, since customer notification is required only after the root cause is fully understoodWrong. This again defers assessment of notification obligations unnecessarily behind the technical investigation.
B.None, because breach response is solely an IT function with no compliance involvementWrong. Compliance involvement is necessary to assess the firm's notification and remediation obligations arising from the breach.
C.None, since a thorough technical root-cause investigation should always be completed before escalating to complianceWrong. This is the exact sequencing error the question warns against; compliance escalation should not wait for the technical investigation to conclude.
D.The firm's incident response should require prompt escalation to compliance upon discovery, running in parallel with the technical investigationCorrect. Prompt escalation to compliance allows notification and remediation obligations to be assessed without waiting for the root-cause investigation to finish.
Why: Waiting for a complete root-cause investigation before escalating a known breach of sensitive customer information to compliance delays the firm's ability to assess its notification and remediation obligations. The principal should expect the firm's incident response procedures to require prompt escalation to compliance upon discovery of a breach, in parallel with the technical investigation, not sequenced after it.
Finance Exam Pro is not affiliated with FINRA, NASAA, or any exam sponsor. Practice questions are original and are not actual exam questions. Rules change — confirm current requirements with the relevant regulator.