CS0-003 Reporting and Communication Practice Question
A security analyst is drafting a communication plan for a suspected data breach involving customer personally identifiable information. Legal counsel advises that notification may be required under multiple regulations. Which of the following should the analyst do FIRST to ensure the communication plan meets regulatory obligations?
⚠ Common exam trap
The trap here is rushing to notify affected parties or the public before confirming which regulations apply, which can lead to legal penalties and inconsistent messaging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify which regulations apply and their specific notification requirements, including timelines and recipients
When a data breach involves regulated data, the first step is to determine which laws apply and what they require. Notification timelines, recipients, and content vary by regulation. Identifying these obligations ensures the communication plan is legally compliant and avoids premature or inadequate disclosures. Only after this analysis should customer, public, or internal communications be drafted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Publish a press release on the corporate website to demonstrate transparency
Why it's wrong here
A public press release may be part of a broader communication strategy, but it is not the first step. Issuing a public statement before determining regulatory obligations could conflict with legal requirements, such as mandated notification sequences or content restrictions. It could also amplify reputational damage if the incident is not yet confirmed. The analyst must first understand the regulatory landscape before deciding on public disclosure.
- ✓
Identify which regulations apply and their specific notification requirements, including timelines and recipients
Why this is correct
Different regulations, such as GDPR, HIPAA, or state breach laws, have distinct notification triggers, timelines, and recipients. Before communicating, the analyst must determine which laws apply based on data type, location, and affected individuals. This ensures the organization meets its legal obligations and avoids penalties. It is the foundational step in building a compliant communication plan, as it dictates what, when, and to whom notifications must be sent.
- ✗
Send an internal email to all employees describing the breach and instructing them not to discuss it
Why it's wrong here
Internal communication is important, but it should not precede the identification of regulatory requirements. Instructing employees to stay silent could be perceived as a cover-up and may conflict with whistleblower protections or legal obligations. The first step is to understand which regulations apply and what they require. Internal messaging should be crafted after legal guidance is obtained to ensure consistency and compliance.
- ✗
Immediately notify all affected customers via email with the details of the breach
Why it's wrong here
Notifying customers before the incident is confirmed and legal requirements are assessed can cause unnecessary panic, damage trust, and potentially violate regulatory procedures. Notification timelines and methods are often prescribed by law and may require coordination with regulators first. Acting prematurely could also compromise the forensic investigation. The analyst should not initiate customer notifications until the incident is validated and legal guidance is obtained.
Go deeper
Related to this question
Learn chapter
Container and Kubernetes Security Analysis
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.