- From
- Maria Lopez <maria.lopez@acme-corp.com>
- To
- soc@acme-corp.com
- Date
- 2026-05-04 14:18 UTC
DLP flagged customer records pasted into an unsanctioned public AI chatbot
Attempt 1 of 1 · cmqx85szo000n0kx9ewzi3chn
This is your first attempt for this scenario. Retry the scenario to generate a side-by-side comparison against your previous response.
Stay on Easy · Cybersecurity
3 signals are blocking advancement to Medium. Keep practicing at Easy until those areas stabilize. (Track: Cybersecurity)
Signals helping
- Dangerous action frequency. None in recent attempts
- Rubric category coverage. 67% average (need ≥ 55%)
Signals blocking advancement
- Recent average score. 65 / 100 (need ≥ 75)
- Recent pass rate. 1 of 5 passed (need ≥ 66%)
- Recent retry improvement trend. Score is regressing (-11.5 pts on later attempts)
# DLP match (endpoint agent) time: 2026-05-04 13:47 UTC user: jordan.kim@acme-corp.com host: JORDAN-WKS action: clipboard paste into browser -> chat.example-ai[.]com (category: Generative AI, UNSANCTIONED) rule hit: "Customer PII (name+email+phone)" x42 rows, "Source code (internal)" x1 block sample: [REDACTED by DLP] 42 rows matching <name,email,phone,acct_id>; ~60 lines of an internal helper script # Web proxy (src=10.12.51.30 JORDAN-WKS) 13:46:55 CONNECT chat.example-ai[.]com:443 ALLOW (no GenAI category block configured) 13:47:10 POST chat.example-ai[.]com/api/conversation (request body not inspected — TLS) 13:51:02 GET chat.example-ai[.]com/ 200 # Tool / account context - chat.example-ai[.]com = public consumer AI chat, PERSONAL login (not SSO, not in the app catalog) - no enterprise data-retention setting, no DPA / contract with this vendor - Support role scope: read access to the customer ticket system + a customer-export report
- Name
- Customer records (42) + internal script snippet via jordan.kim
- Type
- Regulated customer PII export + internal source snippet pasted into an unsanctioned public AI chatbot
- Owner
- Customer Support · Jordan Kim (data owner: Support Ops / Privacy)
- Level
- High
From: Incident Response Lead (SOC on-call) To: IT Leadership · Privacy/Legal · Support Ops · Identity/Endpoint Admin · On-call SOC Subject: [SEV-3][INC-CYB-AI42] Customer records pasted into unsanctioned public AI chatbot — containment and privacy review in progress Incident: INC-CYB-AI42 · SEV-3 / P3 Status: Investigating — containment and exposure assessment in progress Classification: Cybersecurity · Shadow AI · Sensitive Data Exposure Affected asset: 42 customer records + internal helper script via `jordan.kim@acme-corp.com` Data owner: Support Ops / Privacy Detected: 2026-05-04 14:18 UTC SITUATION & SUMMARY DLP and web proxy telemetry indicate that `jordan.kim@acme-corp.com` used a personal account on an unsanctioned public AI chatbot, `chat.example-ai[.]com`, from the corporate workstation `JORDAN-WKS`. At approximately 13:47 UTC, the endpoint DLP agent detected clipboard paste activity into the browser. The DLP rule matched approximately 42 rows of customer PII containing name, email, phone, and account ID fields, plus approximately 60 lines of an internal helper script. The web proxy confirms a POST to `chat.example-ai[.]com/api/conversation`. The request body was not inspected due to TLS, but the endpoint DLP event provides enough evidence to treat this as a likely sensitive-data exposure. The AI chatbot is not approved, is not in the corporate app catalog, was accessed using a personal login, and has no enterprise data-retention configuration or DPA/contract in place. SEVERITY & PRIORITY This is rated SEV-3 / P3 at this time because the exposed dataset appears limited to 42 customer records and one internal code snippet, but it involves regulated customer PII and an unsanctioned public AI service with no contractual data-protection controls. The privacy and data-exposure assessment should be handled urgently because customer PII may have been submitted to a third-party consumer AI platform outside approved channels. IMMEDIATE CONTAINMENT * Contact Jordan and instruct them to stop using the chatbot immediately. * Instruct Jordan not to delete browser history, chatbot history, local files, screenshots, or any related evidence until SOC and Privacy approve. * Preserve the endpoint DLP alert, including timestamp, host, user, rule hits, and redacted sample metadata. * Preserve web proxy logs showing the connection and POST to `chat.example-ai[.]com`. * Block or temporarily restrict `chat.example-ai[.]com` at the web proxy / DNS layer while the exposure assessment is in progress. * Confirm whether any additional uploads to the same chatbot occurred from `JORDAN-WKS` or Jordan’s account. * Do not wipe or reimage Jordan’s workstation unless separate evidence of malware or endpoint compromise appears. INVESTIGATION * Interview Jordan to determine exactly what was pasted, why it was pasted, whether the chatbot retained the conversation, and whether the output was copied or shared elsewhere. * Ask Jordan to preserve the chatbot conversation and account context. If accessible, collect screenshots or an export through an approved evidence-handling process. * Identify the source of the customer export report and determine whether it was generated legitimately within Jordan’s Support role. * Confirm the exact fields exposed: names, emails, phone numbers, account IDs, and whether any additional sensitive fields were included. * Determine whether the 42 customer records are real production customer records, test data, or mixed data. * Identify whether the internal helper script contains secrets, API keys, credentials, internal URLs, business logic, or security-sensitive implementation details. * Search DLP and proxy logs for other users accessing `chat.example-ai[.]com` or similar unsanctioned GenAI tools. * Review Jordan’s recent browser/proxy activity for additional POSTs to the same service before and after the detected event. * Review whether approved enterprise AI tools were available and whether policy banners, training, or technical controls were missing. PRIVACY / LEGAL REVIEW * Engage Privacy/Legal to determine whether this meets internal incident-reporting or external notification criteria. * Provide Privacy with the minimum necessary facts: number of affected records, data elements involved, vendor/tool name, timestamp, user, and whether the data can be deleted or controlled. * Determine whether the public AI provider’s terms allow retention, model training, human review, or downstream processing of submitted content. * If possible, request deletion of the submitted conversation/data through the provider’s account or privacy process, coordinated by Privacy/Legal. * Do not send raw customer PII in email, chat, or tickets while coordinating the review. EVIDENCE PRESERVATION * Preserve the DLP alert metadata and redacted sample summary. * Preserve web proxy logs for `JORDAN-WKS` and `chat.example-ai[.]com`. * Preserve endpoint telemetry around the clipboard paste event. * Preserve Jordan’s browser history and relevant local artifacts, if policy permits. * Preserve screenshots or exports of the chatbot conversation only through approved evidence-handling procedures. * Preserve a list of the potentially affected customer record IDs in a restricted evidence location. RECOVERY & NEXT STEPS * Complete the data exposure assessment with Support Ops and Privacy. * Confirm whether the internal script contains secrets or sensitive logic. If secrets are found, rotate them immediately. * Remove or delete the chatbot conversation if the provider/account supports deletion and Privacy approves the action. * Restrict or block unsanctioned GenAI services until an approved governance path is in place. * Provide Jordan with targeted coaching on approved AI tools and prohibited data types. * Review whether DLP should block, not only alert, on customer PII pasted into unsanctioned GenAI websites. * Update acceptable-use guidance for public AI tools, especially for customer records, internal code, and ticket exports. STAKEHOLDER COMMUNICATION * Notify Support Ops that 42 customer records may have been exposed through an unsanctioned public AI service. * Notify Privacy/Legal for exposure assessment and notification determination. * Notify Endpoint/Web Security to preserve logs and apply temporary access controls. * Notify Jordan’s manager after initial fact-gathering, avoiding unnecessary disclosure of raw customer data. DO NOT * Do not ask Jordan to paste the chatbot conversation or customer records into email or chat. * Do not share raw PII in the incident ticket unless the ticket is access-restricted and approved for sensitive evidence. * Do not delete the chatbot conversation before evidence is preserved and Privacy/Legal approves deletion. * Do not treat this as malware or wipe the workstation without evidence of endpoint compromise. * Do not assume the exposure is harmless because only 42 records were involved. * Do not close the incident after blocking the website; complete privacy review, data scoping, and control improvement actions.
Solid response — your plan covers the core incident response steps and avoids dangerous actions. Score: 75/100. Strongest area: Clarity & structure (100%). Weakest area: Prioritization (50%) — expand this next time.
Where points came from
- Attack understanding2/3 · 10.0 / 15
- Asset impact3/3 · 10.0 / 10
- Prioritization1/2 · 5.0 / 10
- 3/5 · 12.0 / 20
- Investigation3/4 · 11.3 / 15
- Recovery2/3 · 6.7 / 10
- Evidence preservation3/3 · 10.0 / 10
- Clarity & structure2/2 · 10.0 / 10
Strengths
- Asset impact
- Investigation
- Evidence preservation
- Clarity & structure
Missing / weak
No category dropped below 40%.
Dangerous actions detected
None detected in your response.
Learn from this attempt
Post-submission coaching for this scenario. Score and verdict are unchanged — these notes are for your next attempt.
Why points were deducted
- Prioritization50% coverage
Scope-before-notify: confirm exactly what was exposed first, then bring in the data owner and Privacy/Legal; keep it non-punitive.
- Containment60% coverage
Block the GenAI category / the site at the proxy, stop the user, and request vendor deletion / training opt-out — not just 'talk to Jordan'.
- Attack understanding67% coverage
Name this as shadow-AI / unsanctioned-tool data exposure (sensitive data sent to a third-party GenAI service), not a malware or account-compromise incident.
Model answer outline
A Support user (jordan.kim) pasted ~42 rows of customer PII (name/email/phone/acct_id) plus a ~60-line internal script into a public consumer AI chatbot (chat.example-ai[.]com) from their work laptop, using a personal login on an unsanctioned tool with no DPA and no enterprise data-retention. DLP and the web proxy caught it ~30 minutes ago. This is a shadow-AI data-exposure incident, not malware — the job is to scope what left, contain further exposure, preserve the evidence, and bring in the data owner / Privacy.
Rated SEV-3 / P3. Treat as a P2 confirmed data-exposure: regulated customer PII left to a third party with no contract, but it is bounded and already detected.
- Treat as a P2 confirmed data-exposure: regulated customer PII left to a third party with no contract, but it is bounded and already detected.
- Scope what was exposed BEFORE deciding on notification — the record count and fields drive whether this is a reportable privacy event.
- Loop in the data owner (Support Ops) and Privacy/Legal early; keep it factual and non-punitive so the user keeps cooperating.
- Add a GenAI / unsanctioned-AI category block (and block chat.example-ai[.]com) at the proxy so the same paste cannot be repeated fleet-wide.
- Tell Jordan to stop using the tool and not to paste the data again; do not have anyone re-enter the data to 'test' it.
- Request deletion of the conversation from the vendor and opt out of any training use, and flag the 42 affected account ids to the data owner to watch.
- From the DLP match and proxy log, establish exactly what was pasted (42 PII rows + which fields, and the internal script), not just that 'something' was.
- Check whether Jordan (or others) did this before or with other GenAI sites — one paste or a pattern changes the response.
- Identify the source of the export (which report / ticket query) so the data owner can confirm the records and classification.
- Stand up or point users to a sanctioned AI option so the productivity need that drove the shadow use has a safe path.
- Tighten DLP / proxy policy for GenAI categories and add the lesson to acceptable-use / AI-usage policy.
- Run a short, blameless awareness refresher for Support on what may and may not be pasted into external tools.
- Preserve the DLP match record and the web-proxy log entries (export, do not delete) with the case id.
- Capture a screenshot / record of the tool, account type, and timestamps before any policy change.
- Record the affected record count and fields for the Privacy/Legal assessment.
- Brief the data owner (Support Ops) and Privacy/Legal with the concrete scope (42 records, fields, source).
- Coach Jordan factually on what happened and what to do instead — reporting and cooperation should not feel punished.
- Hold any external/customer notification until Privacy/Legal complete the reportability assessment.
- Do not delete the DLP alert or clear the proxy logs — they are the evidence of what was exposed.
- Do not re-paste the data into the chatbot to 'reproduce' it — that repeats the exposure.
- Do not forward the exposed customer records around over email/chat while investigating.
- Do not jump to discipline before scoping; punitive first moves discourage future reporting.
Dangerous actions to avoid
- Do not delete the DLP alert or clear the proxy logs — they are the evidence of what was exposed.
- Do not re-paste the data into the chatbot to 'reproduce' it — that repeats the exposure.
- Do not forward the exposed customer records around over email/chat while investigating.
- Do not jump to discipline before scoping; punitive first moves discourage future reporting.
How to improve next time
- Shadow AI is a data-governance incident: the core question is always 'what data left, to whom, under what contract' — answer that before anything else.
- Blocking the GenAI category at the proxy contains the whole fleet, not just one user; pair it with a sanctioned alternative so people do not route around it again.
- Never reproduce a data-exposure by re-entering the data — you would be exposing it a second time.
- Scope drives notification: the record count, fields, and customer identities determine whether Privacy/Legal must report it.
- Keep shadow-AI response blameless and factual; punishing the first reporter teaches everyone else to hide the next one.
Request an AI review of this attempt
This AI review is supplemental coaching. It does not change your official score or verdict. The review is only kept for this page session and is not saved permanently.
AI Tutor
This tutor explains your result. It does not change your score. Pick a question to see how the deterministic grading reached your verdict and where to focus next.
Generated deterministically from your graded result — no AI model was called.
Why did I get this score?
Your verdict was Pass at 75/100. That total is the sum of deterministic rubric points across 8 categories — each scores how much of its expected, ordered steps your answer covered, not an opinion about your writing. Your strongest coverage was Asset impact (100%). Points were held back mostly in Prioritization (50%), Containment (60%), Attack understanding (67%).
Re-read the prioritization expectations for this scenario and list the concrete steps you missed.
This tutor explains your existing result. It does not change your score, verdict, or grade. Generated deterministically from your graded result — no AI model was called.
What should I improve first?
Focus on Prioritization first — it is your weakest rubric area at 50% coverage and carries weight 10. For this scenario: Scope-before-notify: confirm exactly what was exposed first, then bring in the data owner and Privacy/Legal; keep it non-punitive.
Rewrite your prioritization section as a short numbered checklist before your next attempt.
This tutor explains your existing result. It does not change your score, verdict, or grade. Generated deterministically from your graded result — no AI model was called.
How does my answer compare to the model answer outline?
Compared with the model answer outline, the most useful sections to study are the ones matching your weak areas. Re-read the outline's prioritization, containment, attack understanding guidance and check which listed points you did not cover. The outline is a high-level checklist of expected points — use it to find gaps, not to copy a finished answer.
Pick one model-answer section you missed and add its key points to your next response in your own words.
This tutor explains your existing result. It does not change your score, verdict, or grade. Generated deterministically from your graded result — no AI model was called.
Which rubric area mattered most here?
Containment mattered most here: it carries the highest rubric weight (20), so coverage there moves your score the most. You covered 60% of it this time, worth 12 points.
Prioritise the highest-weight categories first; make sure containment is fully addressed before lower-weight ones.
This tutor explains your existing result. It does not change your score, verdict, or grade. Generated deterministically from your graded result — no AI model was called.
What should I study next?
Based on this attempt, study prioritization, containment, attack understanding next. Coaching tip for this scenario: Shadow AI is a data-governance incident: the core question is always 'what data left, to whom, under what contract' — answer that before anything else.
Shadow AI is a data-governance incident: the core question is always 'what data left, to whom, under what contract' — answer that before anything else.
This tutor explains your existing result. It does not change your score, verdict, or grade. Generated deterministically from your graded result — no AI model was called.
Coach Notes
Open full notebook →Save study notes for this attempt. They also collect in your mistake notebook.
Loading notes…