CS0-003 Reporting and Communication Practice Question
After a security incident involving a ransomware attack, the organization needs to communicate with various stakeholders. Which THREE of the following are appropriate actions? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place legal holds on relevant data
Customer notification, law enforcement coordination, and legal holds are key communication steps during incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Place legal holds on relevant data
Why this is correct
Placing a legal hold on relevant data is a legally binding directive that suspends all normal deletion, rotation, and destruction policies for potentially relevant information. In a ransomware incident, this preserves logs, endpoint artifacts, and backup copies, ensuring a complete forensic record for litigation or regulatory investigation. Without a legal hold, automated processes such as log rotation or archive purging could destroy evidence, leading to spoliation sanctions and undermining the ability to prove the scope of the breach.
- ✗
Delete all logs to prevent data leakage
Why it's wrong here
Deleting all logs to prevent data leakage is fundamentally flawed because logs are the primary source of evidence for forensic investigators to determine the initial access vector, lateral movement, and exfiltration pathways. Moreover, destruction of logs violates legal preservation obligations and may itself be a criminal act under spoliation statutes. Data leakage is mitigated by access control, encryption, and network monitoring, not by erasing the evidence trail that would expose the attacker's methods.
- ✗
Publish details on social media immediately
Why it's wrong here
Publishing details on social media immediately is dangerous because unverified information can prematurely alert threat actors, allowing them to destroy further evidence or modify their tactics. It can also interfere with an active law enforcement investigation, jeopardizing the chain of custody and potentially violating embargoes. Legal and PR protocols require a coordinated, accurate disclosure after the incident has been assessed and sensitive data redacted, not a public post that may carry legal liability.
- ✓
Coordinate with law enforcement
Why this is correct
Coordinating with law enforcement is a critical step in ransomware response because these attacks are criminal acts, and agencies such as the FBI and CISA can provide threat indicators, decryption tools, and technical assistance. Early engagement preserves evidence through forensically sound acquisition and may be mandatory under specific sector regulations. This action also demonstrates due diligence to regulators and can help in prosecuting the attackers, but it must be balanced with legal counsel to protect internal investigative work product.
- ✓
Notify affected customers as required by law
Why this is correct
Notifying affected customers as required by law is a non-negotiable regulatory obligation under breach notification statutes like GDPR, HIPAA, and various state laws. These laws set strict timelines for notification (e.g., 72 hours under GDPR) and require specific content, including the nature of the breach and mitigation steps. Failure to notify in a legally compliant manner can result in substantial fines and loss of customer trust, and must be done only after forensic analysis confirms data exposure to avoid inaccurate notifications.
Go deeper
Related to this question
Learn chapter
Incident Categories and Severity
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.