hardMultiple Choice
CS0-003 Practice Question: During an active incident, a security analyst…
During an active incident, a security analyst discovers that the attacker has exfiltrated data. The analyst must communicate this to the incident response team. Which method of communication is MOST appropriate?
⚠ Common exam trap
CompTIA often tests the misconception that email or ticketing systems are sufficient for urgent incident communication, when in fact they lack the speed, security, and out-of-band nature required during an active data exfiltration event.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a predefined secure messaging channel or phone call to escalate
During an active incident, speed and security are critical. A predefined secure messaging channel or phone call ensures immediate, confidential communication without the delays or exposure risks of email or ticketing systems. This aligns with NIST SP 800-61 incident response guidelines, which prioritize real-time, out-of-band communication for sensitive updates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Update the incident ticket and wait for the team to review
Why it's wrong here
While updating the ticketing system is necessary for maintaining an accurate audit trail, relying solely on this passive method during an active incident introduces unacceptable latency. Ticketing queues are not constantly monitored in real-time by all responders, meaning critical, time-sensitive updates could sit unread while the threat propagates.
- ✗
Send a detailed email to the incident response team
Why it's wrong here
Email is an asynchronous communication medium that lacks guaranteed immediate delivery and visibility during high-stress incident response scenarios. Responders are often focused on containment and mitigation tasks, meaning an email notification may be overlooked, delaying critical decision-making when seconds count.
- ✓
Use a predefined secure messaging channel or phone call to escalate
Why this is correct
Active incidents require immediate, synchronous communication to coordinate containment efforts and share threat intelligence rapidly. Utilizing out-of-band, pre-established secure channels (such as encrypted chat or direct phone lines) ensures that the escalation is received instantly by the correct personnel without alerting the adversary who may be monitoring the primary network.
- ✗
Post the information on a public forum for awareness
Why it's wrong here
Disclosing active incident details on a public forum violates basic operational security (OPSEC) and non-disclosure agreements, potentially exposing sensitive corporate data or vulnerabilities to malicious actors. This action tips off the adversary that they have been detected, allowing them to alter their tactics, destroy evidence, or accelerate their payload delivery.
Go deeper
Related to this question
Learn chapter
Splunk SPL Queries for Security Analysts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.