hardMultiple ChoiceObjective-mapped
CS0-003 Practice Question: A security analyst discovers that a data breach…
A security analyst discovers that a data breach involving personally identifiable information (PII) of European Union citizens occurred two weeks ago but was not detected until now due to a monitoring gap. The company is subject to GDPR, which requires notification to the relevant supervisory authority within 72 hours of becoming aware of the breach. The analyst reports this to the CISO, who decides to delay notification for another week to prepare a more comprehensive response. The analyst believes this violates regulatory requirements. The analyst has documented the breach details and is concerned about the legal and financial penalties for non-compliance. The company's legal department has a strong compliance focus. The analyst has a duty to escalate within the organization. The organization has a whistleblower policy and an ethics hotline. What should the analyst do?
⚠ Common exam trap
CompTIA often tests the distinction between internal escalation and external reporting, where the trap is that candidates may choose Option C (direct DPA notification) because they confuse an individual's ethical duty with the organizational process required by GDPR, but the correct action is to escalate internally first to allow the organization to fulfill its legal obligation as the data controller.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate the matter to the company's legal department and explain the regulatory requirement for timely notification.
The analyst has a duty to escalate within the organization, and the legal department is the appropriate internal authority to address compliance with GDPR's 72-hour notification requirement. By escalating to legal, the analyst ensures the regulatory obligation is formally raised without bypassing internal hierarchy, which aligns with the company's compliance focus and whistleblower policy. This approach balances the CISO's decision with the legal imperative to notify the supervisory authority within the mandated timeframe.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Document the decision and the delay, then proceed with the notification after one week as instructed.
Why it's wrong here
While documenting the CISO's decision and the delay might seem prudent, it does not absolve the organization of its regulatory obligations. Proceeding with notification after one week, when regulations like GDPR often mandate reporting within 72 hours, still constitutes a clear violation. This action would expose the company to significant fines and reputational damage, as documentation merely records the non-compliant act rather than rectifying it.
- ✓
Escalate the matter to the company's legal department and explain the regulatory requirement for timely notification.
Why this is correct
Escalating the matter to the company's legal department is the most appropriate action because legal counsel is responsible for ensuring compliance with all applicable laws and regulations, including data protection mandates. This allows the legal team to assess the risk of non-compliance and advise on the correct course of action, potentially overriding the CISO's decision while respecting internal authority structures. It ensures the organization acts within legal boundaries.
- ✗
Report the incident to the data protection authority (DPA) immediately, bypassing the CISO, as required by GDPR.
Why it's wrong here
Reporting the incident directly to the Data Protection Authority (DPA) immediately, bypassing the CISO and other internal channels, is generally not the initial step in incident response. While GDPR requires timely DPA notification, organizations typically have established internal escalation procedures that should be followed first. Bypassing these internal processes can lead to a disorganized response, lack of unified organizational strategy, and potential internal disciplinary action, even if the intent is to comply.
- ✗
Follow the CISO's orders and delay the notification.
Why it's wrong here
Directly following the CISO's order to delay notification, especially when aware of regulatory requirements such as GDPR's 72-hour rule, would make the analyst complicit in a non-compliant action. This could lead to severe legal and financial repercussions for the organization, including substantial fines up to 4% of global annual turnover, and could also jeopardize the analyst's professional standing and ethical obligations. Compliance with legal mandates always supersedes direct orders that violate those mandates.
Go deeper
Related to this question
Learn chapter
Endpoint Detection and Response
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.