mediumMultiple Choice
CS0-003 Practice Question: After a major security incident, a post-incident…
After a major security incident, a post-incident review reveals that communication between the SOC and the network operations center (NOC) was slow and unclear. Which document should be updated to improve future incident response?
⚠ Common exam trap
CompTIA often tests your ability to identify the correct security-specific document. Do not be distracted by project management terms like 'Communication management plan' just because the question mentions a communication failure. Communication protocols, escalation paths, and contact lists for security incidents are defined within the Incident Response Plan (IRP) or its associated playbooks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident response plan (IRP)
The Incident Response Plan (IRP) is the primary document that outlines the phases of incident response, including the communication pathways, escalation procedures, and coordination protocols between internal teams (such as the SOC and NOC) and external stakeholders. When a post-incident review (lessons learned) identifies communication delays and lack of clarity between teams, the IRP must be updated to define clearer communication channels and responsibilities for future incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disaster recovery plan (DRP)
Why it's wrong here
The Disaster Recovery Plan (DRP) is primarily concerned with the technical recovery of IT systems, infrastructure, and data after a catastrophic event. Its focus is on restoring technological capabilities, such as servers, networks, and applications, to an operational state. While DRPs may briefly mention notification procedures, they do not govern the strategic or tactical communication protocols with internal and external stakeholders during or after a security incident.
- ✗
Communication management plan
Why it's wrong here
A Communication Management Plan specifically outlines the strategies, protocols, and responsibilities for disseminating information to internal and external stakeholders during and after security incidents. It defines who communicates what, when, through which channels, and to whom, ensuring consistent and timely messaging. Post-incident reviews frequently identify areas for improvement in stakeholder communication, making this the appropriate document to update to enhance future incident handling and transparency.
- ✗
Business continuity plan (BCP)
Why it's wrong here
The Business Continuity Plan (BCP) is a comprehensive strategy designed to ensure the continued operation of critical business functions during and after a disruptive event. While it encompasses broader organizational resilience, including the recovery of essential processes and resources, its primary objective is maintaining operational viability. The BCP focuses on sustaining core business activities rather than detailing the specific communication strategies or protocols for incident-related information dissemination.
- ✓
Incident response plan (IRP)
Why this is correct
The Incident Response Plan (IRP) provides a structured approach for an organization to prepare for, detect, contain, eradicate, recover from, and post-incident review security incidents. While an IRP will include steps for notifying relevant parties and escalating issues, its core focus is on the technical and procedural actions required to mitigate the incident itself. It details the technical steps for analysis and remediation, rather than the overarching strategic framework for stakeholder communication.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.