Courseiva
Reporting and CommunicationhardMultiple SelectObjective-mapped

CS0-003 Reporting and Communication Practice Question

After a security incident involving a ransomware attack, the organization needs to communicate with various stakeholders. Which THREE of the following are appropriate actions? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Place legal holds on relevant data

Customer notification, law enforcement coordination, and legal holds are key communication steps during incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Place legal holds on relevant data

    Why this is correct

    Placing a legal hold on relevant data is a legally binding directive that suspends all normal deletion, rotation, and destruction policies for potentially relevant information. In a ransomware incident, this preserves logs, endpoint artifacts, and backup copies, ensuring a complete forensic record for litigation or regulatory investigation. Without a legal hold, automated processes such as log rotation or archive purging could destroy evidence, leading to spoliation sanctions and undermining the ability to prove the scope of the breach.

  • Delete all logs to prevent data leakage

    Why it's wrong here

    Deleting all logs to prevent data leakage is fundamentally flawed because logs are the primary source of evidence for forensic investigators to determine the initial access vector, lateral movement, and exfiltration pathways. Moreover, destruction of logs violates legal preservation obligations and may itself be a criminal act under spoliation statutes. Data leakage is mitigated by access control, encryption, and network monitoring, not by erasing the evidence trail that would expose the attacker's methods.

  • Publish details on social media immediately

    Why it's wrong here

    Publishing details on social media immediately is dangerous because unverified information can prematurely alert threat actors, allowing them to destroy further evidence or modify their tactics. It can also interfere with an active law enforcement investigation, jeopardizing the chain of custody and potentially violating embargoes. Legal and PR protocols require a coordinated, accurate disclosure after the incident has been assessed and sensitive data redacted, not a public post that may carry legal liability.

  • Coordinate with law enforcement

    Why this is correct

    Coordinating with law enforcement is a critical step in ransomware response because these attacks are criminal acts, and agencies such as the FBI and CISA can provide threat indicators, decryption tools, and technical assistance. Early engagement preserves evidence through forensically sound acquisition and may be mandatory under specific sector regulations. This action also demonstrates due diligence to regulators and can help in prosecuting the attackers, but it must be balanced with legal counsel to protect internal investigative work product.

  • Notify affected customers as required by law

    Why this is correct

    Notifying affected customers as required by law is a non-negotiable regulatory obligation under breach notification statutes like GDPR, HIPAA, and various state laws. These laws set strict timelines for notification (e.g., 72 hours under GDPR) and require specific content, including the nature of the breach and mitigation steps. Failure to notify in a legally compliant manner can result in substantial fines and loss of customer trust, and must be done only after forensic analysis confirms data exposure to avoid inaccurate notifications.

About these practice questions

One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.