Courseiva
hardMultiple Choice

CS0-003 Practice Question: During an active incident, a security analyst…

During an active incident, a security analyst discovers that the attacker has exfiltrated data. The analyst must communicate this to the incident response team. Which method of communication is MOST appropriate?

⚠ Common exam trap

CompTIA often tests the misconception that email or ticketing systems are sufficient for urgent incident communication, when in fact they lack the speed, security, and out-of-band nature required during an active data exfiltration event.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a predefined secure messaging channel or phone call to escalate

During an active incident, speed and security are critical. A predefined secure messaging channel or phone call ensures immediate, confidential communication without the delays or exposure risks of email or ticketing systems. This aligns with NIST SP 800-61 incident response guidelines, which prioritize real-time, out-of-band communication for sensitive updates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Update the incident ticket and wait for the team to review

    Why it's wrong here

    While updating the ticketing system is necessary for maintaining an accurate audit trail, relying solely on this passive method during an active incident introduces unacceptable latency. Ticketing queues are not constantly monitored in real-time by all responders, meaning critical, time-sensitive updates could sit unread while the threat propagates.

  • ✗

    Send a detailed email to the incident response team

    Why it's wrong here

    Email is an asynchronous communication medium that lacks guaranteed immediate delivery and visibility during high-stress incident response scenarios. Responders are often focused on containment and mitigation tasks, meaning an email notification may be overlooked, delaying critical decision-making when seconds count.

  • ✓

    Use a predefined secure messaging channel or phone call to escalate

    Why this is correct

    Active incidents require immediate, synchronous communication to coordinate containment efforts and share threat intelligence rapidly. Utilizing out-of-band, pre-established secure channels (such as encrypted chat or direct phone lines) ensures that the escalation is received instantly by the correct personnel without alerting the adversary who may be monitoring the primary network.

  • ✗

    Post the information on a public forum for awareness

    Why it's wrong here

    Disclosing active incident details on a public forum violates basic operational security (OPSEC) and non-disclosure agreements, potentially exposing sensitive corporate data or vulnerabilities to malicious actors. This action tips off the adversary that they have been detected, allowing them to alter their tactics, destroy evidence, or accelerate their payload delivery.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.