mediumMultiple Select
CS0-003 Practice Question: A tabletop exercise reveals that no one knows who…
A tabletop exercise reveals that no one knows who can approve public statements. What should be updated? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the distinction between technical controls (like signature databases) and procedural/communication controls (like approval roles and contact lists), trapping candidates who confuse operational security tools with incident management processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Contact list and escalation matrix
The tabletop exercise revealed a gap in the incident response process: no one knows who can approve public statements. This is a procedural and communication failure, not a technical one. Updating the incident communication plan with named approval roles (Option D) directly addresses this by defining the specific person or role authorized to speak publicly. The contact list and escalation matrix (Option B) must also be updated to ensure the correct approver can be reached quickly, as it provides the hierarchical path and contact details needed to execute the plan.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The office seating plan only
Why it's wrong here
An office seating plan is a purely administrative document detailing the physical location of personnel within a facility. It provides no information regarding an individual's roles, responsibilities, or delegated authority for incident response approvals. Relying solely on a seating chart would be entirely ineffective for determining who can approve critical actions or communications during an incident, as it does not define organizational hierarchy or decision-making power.
- ✓
Contact list and escalation matrix
Why this is correct
A contact list and escalation matrix is a critical incident response document that explicitly outlines key personnel, their contact information, and the hierarchical path for decision-making and approvals. This matrix clearly defines who needs to be informed and, crucially, who possesses the authority to approve specific actions or communications at each stage of an incident. It directly addresses the problem of unknown approval authority by providing a structured, actionable guide for incident responders.
- ✗
The malware signature database only
Why it's wrong here
A malware signature database is a technical repository containing patterns and characteristics used by security tools to identify known malicious software. While essential for detection and prevention, it is entirely unrelated to defining organizational roles, responsibilities, or approval authorities within an incident response framework. This database provides no guidance on who can approve actions or communications, thus failing to address the identified gap in the tabletop exercise.
- ✓
Incident communication plan with named approval roles
Why this is correct
An incident communication plan specifically details how information will be shared during an incident, including internal and external stakeholders. Crucially, it explicitly names individuals or roles responsible for approving various types of communications and actions, ensuring that decision-making authority is clearly delineated. This plan prevents ambiguity by assigning specific approval responsibilities, thereby streamlining the incident response process and ensuring timely, authorized information dissemination.
Go deeper
Related to this question
Learn chapter
Ransomware Incident Response
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.