Courseiva

CS0-003 Reporting and Communication Practice Question

A security analyst is drafting a communication plan for a suspected data breach involving customer personally identifiable information. Legal counsel advises that notification may be required under multiple regulations. Which of the following should the analyst do FIRST to ensure the communication plan meets regulatory obligations?

⚠ Common exam trap

The trap here is rushing to notify affected parties or the public before confirming which regulations apply, which can lead to legal penalties and inconsistent messaging.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify which regulations apply and their specific notification requirements, including timelines and recipients

When a data breach involves regulated data, the first step is to determine which laws apply and what they require. Notification timelines, recipients, and content vary by regulation. Identifying these obligations ensures the communication plan is legally compliant and avoids premature or inadequate disclosures. Only after this analysis should customer, public, or internal communications be drafted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Publish a press release on the corporate website to demonstrate transparency

    Why it's wrong here

    A public press release may be part of a broader communication strategy, but it is not the first step. Issuing a public statement before determining regulatory obligations could conflict with legal requirements, such as mandated notification sequences or content restrictions. It could also amplify reputational damage if the incident is not yet confirmed. The analyst must first understand the regulatory landscape before deciding on public disclosure.

  • ✓

    Identify which regulations apply and their specific notification requirements, including timelines and recipients

    Why this is correct

    Different regulations, such as GDPR, HIPAA, or state breach laws, have distinct notification triggers, timelines, and recipients. Before communicating, the analyst must determine which laws apply based on data type, location, and affected individuals. This ensures the organization meets its legal obligations and avoids penalties. It is the foundational step in building a compliant communication plan, as it dictates what, when, and to whom notifications must be sent.

  • ✗

    Send an internal email to all employees describing the breach and instructing them not to discuss it

    Why it's wrong here

    Internal communication is important, but it should not precede the identification of regulatory requirements. Instructing employees to stay silent could be perceived as a cover-up and may conflict with whistleblower protections or legal obligations. The first step is to understand which regulations apply and what they require. Internal messaging should be crafted after legal guidance is obtained to ensure consistency and compliance.

  • ✗

    Immediately notify all affected customers via email with the details of the breach

    Why it's wrong here

    Notifying customers before the incident is confirmed and legal requirements are assessed can cause unnecessary panic, damage trust, and potentially violate regulatory procedures. Notification timelines and methods are often prescribed by law and may require coordination with regulators first. Acting prematurely could also compromise the forensic investigation. The analyst should not initiate customer notifications until the incident is validated and legal guidance is obtained.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.