easyMultiple Choice
CS0-003 Practice Question: A small business with 50 employees has been hit…
A small business with 50 employees has been hit by ransomware. All files on the file server and local workstations are encrypted, and the ransom note demands $5,000 in Bitcoin for the decryption key. The CEO is panicking and wants to know the impact on operations and how to proceed. The security analyst has been tasked with preparing a report for the CEO. The company does not have cyber insurance, has minimal IT staff, and relies heavily on email and shared drives for daily operations. The analyst has identified that there is a one-week-old backup but is unsure of its integrity. The analyst must consider that the CEO has limited technical knowledge and that the report will form the basis for critical business decisions. The company's reputation and customer trust are at stake. The analyst must balance transparency with clear, actionable guidance. Which of the following is the BEST approach for the analyst to take in communicating with the CEO?
⚠ Common exam trap
CS0-004 often tests whether candidates can tailor communication to a non-technical audience, and many choose technically detailed answers that fail to address business impact and decision-making needs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Summarize the situation in non-technical terms, explain the business impact (e.g., inability to access customer data, potential revenue loss), outline recovery options (e.g., restore from backups or pay ransom with risks), and recommend immediate steps.
The best approach is to communicate in business terms the CEO can understand: summarize the incident, explain operational and financial impact, present recovery options with risks, and recommend immediate actions. This balances transparency with actionable guidance, enabling informed decision-making.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Provide a detailed technical timeline of the ransomware infection, including the malware variant and encryption algorithm used.
Why it's wrong here
Executive communication during a security incident must focus on business risk and strategic decisions rather than low-level technical details. Presenting a complex timeline of indicators of compromise, specific malware families, or cryptographic algorithms like AES-256 or RSA-2048 overwhelms non-technical leadership and delays critical recovery decisions.
- ✗
Tell the CEO that the incident is being handled and not to worry, then proceed with recovery without further updates.
Why it's wrong here
Withholding information and failing to provide regular updates violates incident response communication standards and destroys executive trust. The CEO bears ultimate fiduciary and legal responsibility for the organization's data assets, meaning they must be kept informed of the incident's scope, regulatory implications, and operational impact.
- ✓
Summarize the situation in non-technical terms, explain the business impact (e.g., inability to access customer data, potential revenue loss), outline recovery options (e.g., restore from backups or pay ransom with risks), and recommend immediate steps.
Why this is correct
Effective incident response requires translating technical findings into business impacts to facilitate rapid executive decision-making. By outlining clear recovery paths, such as restoring from offline backups versus the legal and financial risks of paying a ransom, the security team empowers the CEO to make informed risk-management choices.
- ✗
Immediately contact law enforcement and advise the CEO to wait for their instructions without providing additional information.
Why it's wrong here
While involving law enforcement is a critical step in ransomware response, delegating all decision-making to external agencies causes unacceptable operational downtime. Law enforcement agencies focus on investigation rather than business continuity, meaning the organization must concurrently execute its own incident response and disaster recovery plans to minimize financial damage.
Go deeper
Related to this question
Learn chapter
NIST Incident Response Framework
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.