incident-response-trainer
Incident response training · Rule-based scoring
DemoCatalogDiagnosticHistoryDashboardCoach Notes
Incident

DLP flagged customer records pasted into an unsanctioned public AI chatbot

CybersecurityDifficulty · Easy
← New scenario
Retry in progress
You have 1 previous attempt for this scenario. Submitting again will create a new attempt and show a comparison against your most recent response.
Shadow AI Sensitive-Data ExposureDifficulty · easyHigh asset
DLP alert — customer data + code pasted into a public AI chatbot (shadow AI)
From
Maria Lopez <maria.lopez@acme-corp.com>
To
soc@acme-corp.com
Date
2026-05-04 14:18 UTC
Hi SOC, Our DLP / web proxy flagged a possible data exposure and I want a second opinion before I talk to the user. A Support team member (jordan.kim) used a PERSONAL account on a public AI chatbot from their work laptop and pasted in what looks like a chunk of a customer export plus a snippet of an internal script. This is NOT one of our approved tools — it is "shadow AI". The paste was about 30 minutes ago. Jordan says they were "just trying to summarize a ticket backlog faster". I have the DLP match details and the proxy log. I have not contacted Jordan yet and I have not changed anything. What is the right order of steps, and how do I work out exactly what was exposed and who needs to know? — Maria (SOC, Tier 1)
Evidence
DLP match summary + web-proxy log excerpt (JORDAN-WKS)
# DLP match (endpoint agent)
time:      2026-05-04 13:47 UTC
user:      jordan.kim@acme-corp.com   host: JORDAN-WKS
action:    clipboard paste into browser -> chat.example-ai[.]com (category: Generative AI, UNSANCTIONED)
rule hit:  "Customer PII (name+email+phone)" x42 rows, "Source code (internal)" x1 block
sample:    [REDACTED by DLP] 42 rows matching <name,email,phone,acct_id>; ~60 lines of an internal helper script

# Web proxy (src=10.12.51.30 JORDAN-WKS)
13:46:55  CONNECT chat.example-ai[.]com:443   ALLOW (no GenAI category block configured)
13:47:10  POST    chat.example-ai[.]com/api/conversation   (request body not inspected — TLS)
13:51:02  GET     chat.example-ai[.]com/   200

# Tool / account context
- chat.example-ai[.]com = public consumer AI chat, PERSONAL login (not SSO, not in the app catalog)
- no enterprise data-retention setting, no DPA / contract with this vendor
- Support role scope: read access to the customer ticket system + a customer-export report
Affected asset
Name
Customer records (42) + internal script snippet via jordan.kim
Type
Regulated customer PII export + internal source snippet pasted into an unsanctioned public AI chatbot
Owner
Customer Support · Jordan Kim (data owner: Support Ops / Privacy)
Level
High
0 words

Grading is rule-based. Response is compared against a pre-written rubric.