What is the Next Step After Confirming a Proprietary Data Breach?

A company discovered its data was advertised for sale on the dark web. During the initial investigation, the company determined the data was proprietary data. Which of the following is the next step the company should take?

  1. Identify the attacker’s entry methods.
  2. Report the breach to the local authorities.
  3. Notify the applicable parties of the breach. Source Reference Answer
  4. Implement vulnerability scanning of the company's systems.

Community Votes

C
64%
B
36%

64% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests knowledge of incident response prioritization, where candidates often mistakenly jump to law enforcement or forensic analysis instead of fulfilling mandatory breach notification obligations.

This question tests the proper sequence of actions during a confirmed data breach, emphasizing regulatory and stakeholder notification over immediate forensic or law enforcement steps. The community consensus aligns with CompTIA’s guidance that notifying applicable parties and complying with legal requirements takes priority once a breach is verified.

Many candidates choose B (Report to local authorities) because they associate dark web sales with criminal activity requiring police involvement, but CompTIA prioritizes legal compliance and stakeholder notification first per standard incident response frameworks.

Community Discussion (7 comments)

Fourgehan 👍 8 Selected: C
When a company discovers that proprietary data has been compromised and advertised for sale on the dark web, the next step is to notify the applicable parties of the breach. This typically includes: Internal stakeholders (e.g., management, legal, and compliance teams) to ensure they are aware of the situation. Affected individuals or entities (e.g., customers, partners, employees) who may be impacted by the data breach. Regulatory authorities (depending on the jurisdiction and nature of the breach, such as GDPR for EU residents, or similar data protection laws elsewhere) to ensure compliance with breach notification laws. Prompt notification helps mitigate the impact, provide guidance to affected parties, and ensure that any required legal or regulatory actions are taken
JoeRealCool 👍 1 Selected: B
Data being exfiltrated and sold on the dark web is not legal. It might be required by regulations to notify the local authorities first.
CSue 👍 1 Selected: A
Since proprietary data has already been leaked, the next critical step is to determine how the attacker gained access to prevent further breaches. This involves: - Reviewing logs to identify unauthorized access. - Analyzing network activity to find anomalies. - Checking for exploited vulnerabilities or compromised credentials. Without understanding the entry method, the company cannot effectively contain the breach or prevent similar incidents in the future. Why containment comes first: If the breach is still ongoing, attackers may still have access, making notifications premature. - Understanding the attack vector allows the company to stop further data exfiltration and ensure accurate reporting. Regulatory bodies and affected parties will likely ask: - How did the breach happen? - What data was accessed? - What remediation steps are in place? Without containment and investigation, the company may provide incomplete or incorrect information. Therefore Answer A: Identify the attackers's entry methods is the correct answer
jbmac 👍 3 Selected: B
The correct answer is: B. Report the breach to the local authorities. Explanation: Once a company discovers that its proprietary data has been advertised for sale on the dark web, it is crucial to involve law enforcement. Reporting the breach to the local authorities ensures that the incident is formally recorded and investigated. Authorities can assist in tracking down the perpetrators, determining the scope of the breach, and taking legal action. In many jurisdictions, reporting data breaches involving sensitive or proprietary data is not only best practice but may also be a legal requirement.
ProudFather 👍 2 Selected: C
The first step after discovering a data breach is to notify the affected parties. This includes notifying customers, employees, and regulatory authorities, as required by applicable laws and regulations. The specific notification requirements will vary depending on the jurisdiction and the nature of the data that was breached.
AriGarcia 👍 4 Selected: C
The next step after discovering a breach is to comply with legal and regulatory obligations, which often include notifying affected or applicable parties. This could involve: Informing customers or business partners whose data was compromised. Meeting compliance requirements for breach notifications under laws like GDPR or CCPA. While reporting might be necessary depending on the jurisdiction, it usually follows notifying affected parties as per breach notification requirements.
chasingsummer 👍 4 Selected: B
Once a company discovers that proprietary data has been compromised and is being sold on the dark web, it is critical to report the breach to the authorities. This is important for several reasons: Legal requirements: Many regions have laws and regulations that mandate reporting data breaches to authorities, especially when sensitive or proprietary data is involved. Investigation: Law enforcement can assist in investigating the breach, tracking the attackers, and taking further legal action. Collaboration: Authorities may have additional resources or intelligence that can aid in understanding the scale of the breach and identifying the attackers.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Incident Response Prioritization

Once a data breach is confirmed, the organization must immediately pivot to notification and compliance. CompTIA’s incident response framework aligns with NIST guidelines, which treat stakeholder and regulatory notification as a critical parallel track that should not be delayed by lengthy forensic investigations. Notifying applicable parties fulfills legal obligations under regulations like GDPR, CCPA, or industry-specific mandates, which often carry strict timelines.

Why Other Options Are Incorrect

Identifying the attacker’s entry methods (Option A) is part of the containment and eradication phase, but delaying notification to complete forensics violates compliance deadlines and increases liability. Understanding the attack vector is vital for prevention, but it does not supersede mandatory breach disclosure. Reporting to local authorities (Option B) may be required in specific jurisdictions or for certain data types, but it is not a universal immediate next step. Law enforcement involvement typically follows internal triage and legal review, whereas stakeholder notification has broader, time-sensitive requirements. Implementing vulnerability scanning (Option D) is a proactive security control used during the preparation or post-incident hardening phases, not a reactive measure during an active breach response.

Community Consensus & Practical Application

The majority of test-takers correctly selected C, recognizing that proprietary data leaks trigger legal and reputational risk management protocols. While some argued for law enforcement involvement due to the dark web context, CompTIA consistently prioritizes structured communication with affected entities and compliance teams. In real-world scenarios, this mirrors how organizations activate their Incident Response Plan (IRP), engaging legal counsel to draft notifications while technical teams investigate.

Official Reference

Exam Strategy

Always map breach scenarios to the incident response lifecycle and look for options that address legal, compliance, and stakeholder communication first when a breach is confirmed. Avoid jumping to technical remediation or law enforcement unless the scenario explicitly states that notifications have already been handled or that jurisdictional mandates require immediate police involvement.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide