Courseiva
hardMultiple ChoiceObjective-mapped

CS0-003 Practice Question: A security analyst discovers that a data breach…

A security analyst discovers that a data breach involving personally identifiable information (PII) of European Union citizens occurred two weeks ago but was not detected until now due to a monitoring gap. The company is subject to GDPR, which requires notification to the relevant supervisory authority within 72 hours of becoming aware of the breach. The analyst reports this to the CISO, who decides to delay notification for another week to prepare a more comprehensive response. The analyst believes this violates regulatory requirements. The analyst has documented the breach details and is concerned about the legal and financial penalties for non-compliance. The company's legal department has a strong compliance focus. The analyst has a duty to escalate within the organization. The organization has a whistleblower policy and an ethics hotline. What should the analyst do?

⚠ Common exam trap

CompTIA often tests the distinction between internal escalation and external reporting, where the trap is that candidates may choose Option C (direct DPA notification) because they confuse an individual's ethical duty with the organizational process required by GDPR, but the correct action is to escalate internally first to allow the organization to fulfill its legal obligation as the data controller.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Escalate the matter to the company's legal department and explain the regulatory requirement for timely notification.

The analyst has a duty to escalate within the organization, and the legal department is the appropriate internal authority to address compliance with GDPR's 72-hour notification requirement. By escalating to legal, the analyst ensures the regulatory obligation is formally raised without bypassing internal hierarchy, which aligns with the company's compliance focus and whistleblower policy. This approach balances the CISO's decision with the legal imperative to notify the supervisory authority within the mandated timeframe.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Document the decision and the delay, then proceed with the notification after one week as instructed.

    Why it's wrong here

    While documenting the CISO's decision and the delay might seem prudent, it does not absolve the organization of its regulatory obligations. Proceeding with notification after one week, when regulations like GDPR often mandate reporting within 72 hours, still constitutes a clear violation. This action would expose the company to significant fines and reputational damage, as documentation merely records the non-compliant act rather than rectifying it.

  • Escalate the matter to the company's legal department and explain the regulatory requirement for timely notification.

    Why this is correct

    Escalating the matter to the company's legal department is the most appropriate action because legal counsel is responsible for ensuring compliance with all applicable laws and regulations, including data protection mandates. This allows the legal team to assess the risk of non-compliance and advise on the correct course of action, potentially overriding the CISO's decision while respecting internal authority structures. It ensures the organization acts within legal boundaries.

  • Report the incident to the data protection authority (DPA) immediately, bypassing the CISO, as required by GDPR.

    Why it's wrong here

    Reporting the incident directly to the Data Protection Authority (DPA) immediately, bypassing the CISO and other internal channels, is generally not the initial step in incident response. While GDPR requires timely DPA notification, organizations typically have established internal escalation procedures that should be followed first. Bypassing these internal processes can lead to a disorganized response, lack of unified organizational strategy, and potential internal disciplinary action, even if the intent is to comply.

  • Follow the CISO's orders and delay the notification.

    Why it's wrong here

    Directly following the CISO's order to delay notification, especially when aware of regulatory requirements such as GDPR's 72-hour rule, would make the analyst complicit in a non-compliant action. This could lead to severe legal and financial repercussions for the organization, including substantial fines up to 4% of global annual turnover, and could also jeopardize the analyst's professional standing and ethical obligations. Compliance with legal mandates always supersedes direct orders that violate those mandates.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.