Courseiva
Reporting and CommunicationhardMultiple SelectObjective-mapped

CS0-003 Reporting and Communication Practice Question

An organization has experienced a data breach involving personal information of EU residents. The incident response team is preparing communications. Which THREE of the following are mandatory actions under GDPR? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Notify all affected data subjects without undue delay if high risk

GDPR requires notification to the supervisory authority within 72 hours, documentation of the breach, and notification to affected individuals if high risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Notify all affected data subjects without undue delay if high risk

    Why this is correct

    GDPR Article 34 mandates that data controllers must notify affected data subjects without undue delay when a personal data breach is likely to result in a high risk to their rights and freedoms. This direct communication enables individuals to take necessary precautions to mitigate potential harm, such as identity theft or financial fraud. The 'without undue delay' clause emphasizes the urgency of informing those directly impacted by the breach.

  • Document the breach and remediation actions

    Why this is correct

    Under the GDPR's accountability principle, organizations are obligated to document any personal data breaches, including the facts relating to the breach, its effects, and the remedial actions taken. This comprehensive record-keeping is crucial for demonstrating compliance with the regulation to supervisory authorities and for internal review. Such documentation supports continuous improvement in security practices and helps prevent future incidents.

  • Publish a public notice in the local newspaper

    Why it's wrong here

    Publishing a public notice in a local newspaper is not a primary or standalone requirement under GDPR for data breach notification. While Article 34 allows for public communication if direct notification to data subjects is not feasible or would involve disproportionate effort, it is typically a last resort or supplementary measure. GDPR primarily emphasizes direct, individualized notification to affected data subjects when high risk is present.

  • Notify law enforcement within 24 hours

    Why it's wrong here

    The GDPR does not specifically mandate notifying law enforcement within a 24-hour timeframe for a data breach. Its primary focus for external notification is the relevant supervisory authority and, if applicable, the affected data subjects. While other national laws or sector-specific regulations might require law enforcement notification, this is not a universal GDPR provision, and the 24-hour period is not specified by GDPR.

  • Notify the supervisory authority within 72 hours

    Why this is correct

    GDPR Article 33 requires data controllers to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it. This notification is mandatory unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The purpose is to enable the authority to assess the situation and ensure appropriate measures are taken.

About these practice questions

One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.