easyMultiple ChoiceObjective-mapped
CS0-003 Practice Question: A medium-sized company has experienced a…
A medium-sized company has experienced a ransomware attack that encrypted critical file servers. The incident response team has contained the outbreak and restored data from backups. The CISO has requested a post-incident report. The report must include a timeline, root cause analysis, lessons learned, and recommendations. The security team is currently overwhelmed with recovery tasks. The CISO wants the report delivered in 24 hours. Which of the following is the BEST course of action for the security analyst assigned to write the report?
⚠ Common exam trap
CompTIA often tests the tension between thoroughness and timeliness in incident reporting, and the trap here is that candidates may choose to wait for complete data (Option A) or delegate (Option B) instead of using a structured template to meet the deadline while acknowledging information gaps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the incident response playbook template to draft the report immediately, incorporating available information and noting gaps
The CISO needs a timely post-incident report within 24 hours, and using the incident response playbook template allows the analyst to immediately draft the report with available information while noting gaps. This approach balances the urgency of the deadline with the need for structured documentation, even though recovery tasks are ongoing. It ensures that critical findings are captured promptly without waiting for full recovery, which could delay lessons learned and recommendations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wait until all recovery tasks are complete to ensure accurate information
Why it's wrong here
Incident response best practices, often guided by frameworks like NIST SP 800-61, emphasize timely communication to stakeholders. Waiting for full recovery before drafting an initial report would significantly delay critical notification, potentially violating regulatory reporting requirements or internal service level agreements (SLAs). Initial reports are expected to be dynamic, providing a snapshot of known information, even if incomplete, to enable informed decision-making and maintain transparency during an evolving crisis.
- ✗
Delegate the report writing to a junior analyst while focusing on technical recovery
Why it's wrong here
While delegation can be appropriate for certain tasks, the primary incident responder or lead analyst is typically best positioned to draft the initial report due to their direct involvement and comprehensive understanding of the incident's technical nuances and impact. Delegating this critical task to a junior analyst, especially during an active recovery, risks introducing inaccuracies, missing key details, or failing to convey the appropriate level of urgency and technical depth required for executive-level communication. The lead analyst maintains ownership and accountability for the report's quality and content.
- ✓
Use the incident response playbook template to draft the report immediately, incorporating available information and noting gaps
Why this is correct
Leveraging an established incident response playbook template for report drafting is a highly effective strategy, especially under time constraints. This approach ensures that critical information fields are addressed systematically, even if initial data is incomplete, and allows for the immediate documentation of known facts, timelines, and current status. By explicitly noting information gaps, the report remains transparent about its current state, facilitates timely communication to stakeholders, and provides a structured framework for subsequent updates and refinements as recovery progresses.
- ✗
Request an extension from the CISO due to resource constraints
Why it's wrong here
Requesting an extension from the CISO for an initial incident report, particularly within a standard 24-hour timeframe, should be considered a last resort. Such a request implies a failure to manage immediate reporting requirements and can undermine confidence in the incident response team's ability to operate efficiently under pressure. A preliminary report, even if brief and acknowledging ongoing investigation, is generally expected within the initial reporting window to keep leadership informed and demonstrate proactive management of the incident, rather than delaying communication entirely.
Go deeper
Related to this question
Learn chapter
SIEM Log Analysis
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.