CS0-003 Reporting and Communication Practice Question
During an incident, the SOC team identifies indicators of compromise (IoCs) that may affect partners. According to best practices, what should the analyst do first?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Follow the incident response communication plan
An incident response plan should define communication procedures; typically, the team should escalate internally to leadership who can authorize external notifications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Follow the incident response communication plan
Why this is correct
Adhering to the pre-established incident response communication plan ensures that all internal and external stakeholders are notified in a controlled, legally compliant, and authorized manner. This plan defines specific roles, escalation paths, and approved channels, preventing unauthorized disclosures that could compromise the active investigation or violate regulatory requirements.
- ✗
Wait until the incident is fully resolved
Why it's wrong here
Postponing communication until complete eradication and recovery are achieved can severely expose third-party partners to active threats stemming from the breach. Many compliance frameworks and service level agreements (SLAs) mandate timely disclosure of active incidents to mitigate downstream supply chain risks and allow partners to defend their own networks.
- ✗
Post the IoCs on a public threat sharing platform
Why it's wrong here
Publishing indicators of compromise (IoCs) to public repositories without explicit authorization can tip off the threat actors that they have been detected, prompting them to alter their tactics and clean their tracks. Furthermore, leaking sensitive operational data prematurely can damage the organization's reputation and violate non-disclosure agreements with partners.
- ✗
Directly notify all affected partners
Why it's wrong here
Bypassing the established chain of command to directly contact partners can lead to inconsistent messaging, legal liabilities, and unnecessary panic. Communication must be vetted by legal, public relations, and executive leadership to ensure that the information shared is accurate, authorized, and aligned with contractual obligations.
Go deeper
Related to this question
Learn chapter
Data Breach Incident Response
Key term
SOC
A Security Operations Center (SOC) is a centralized team that monitors, detects, analyzes, and responds to cybersecurity incidents to protect an organization's information systems.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.