CS0-003 Reporting and Communication Practice Question
An organization has experienced a data breach involving personal information of EU residents. The incident response team is preparing communications. Which THREE of the following are mandatory actions under GDPR? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Notify all affected data subjects without undue delay if high risk
GDPR requires notification to the supervisory authority within 72 hours, documentation of the breach, and notification to affected individuals if high risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Notify all affected data subjects without undue delay if high risk
Why this is correct
GDPR Article 34 mandates that data controllers must notify affected data subjects without undue delay when a personal data breach is likely to result in a high risk to their rights and freedoms. This direct communication enables individuals to take necessary precautions to mitigate potential harm, such as identity theft or financial fraud. The 'without undue delay' clause emphasizes the urgency of informing those directly impacted by the breach.
- ✓
Document the breach and remediation actions
Why this is correct
Under the GDPR's accountability principle, organizations are obligated to document any personal data breaches, including the facts relating to the breach, its effects, and the remedial actions taken. This comprehensive record-keeping is crucial for demonstrating compliance with the regulation to supervisory authorities and for internal review. Such documentation supports continuous improvement in security practices and helps prevent future incidents.
- ✗
Publish a public notice in the local newspaper
Why it's wrong here
Publishing a public notice in a local newspaper is not a primary or standalone requirement under GDPR for data breach notification. While Article 34 allows for public communication if direct notification to data subjects is not feasible or would involve disproportionate effort, it is typically a last resort or supplementary measure. GDPR primarily emphasizes direct, individualized notification to affected data subjects when high risk is present.
- ✗
Notify law enforcement within 24 hours
Why it's wrong here
The GDPR does not specifically mandate notifying law enforcement within a 24-hour timeframe for a data breach. Its primary focus for external notification is the relevant supervisory authority and, if applicable, the affected data subjects. While other national laws or sector-specific regulations might require law enforcement notification, this is not a universal GDPR provision, and the 24-hour period is not specified by GDPR.
- ✓
Notify the supervisory authority within 72 hours
Why this is correct
GDPR Article 33 requires data controllers to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it. This notification is mandatory unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The purpose is to enable the authority to assess the situation and ensure appropriate measures are taken.
Go deeper
Related to this question
Learn chapter
Endpoint Detection and Response
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.