exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 238 discussion

Actual exam question from CompTIA's CS0-003
Question #: 238
Topic #: 1
[All CS0-003 Questions]

An organization discovered a data breach that resulted in PII being released to the public. During the lessons learned review, the panel identified discrepancies regarding who was responsible for external reporting, as well as the timing requirements. Which of the following actions would best address the reporting issue?

  • A. Creating a playbook denoting specific SLAs and containment actions per incident type
  • B. Researching federal laws, regulatory compliance requirements, and organizational policies to document specific reporting SLAs
  • C. Defining which security incidents require external notifications and incident reporting in addition to internal stakeholders
  • D. Designating specific roles and responsibilities within the security team and stakeholders to streamline tasks
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
LB54
Highly Voted 9 months, 4 weeks ago
Selected Answer: B
The best approach to address the reporting issue in this scenario would be Option B: researching federal laws, regulatory compliance requirements, and organizational policies to document specific reporting Service Level Agreements (SLAs). By understanding the legal and regulatory landscape, the organization can establish clear guidelines for external reporting, ensuring timely and accurate notifications when incidents occur. This proactive approach helps prevent discrepancies and ensures compliance with reporting obligations.
upvoted 7 times
Chiniwini
9 months, 2 weeks ago
This is important for ensuring compliance, but it does not solve the problem of unclear responsibilities. Knowing the laws and SLAs is crucial, but without designated roles, there could still be confusion about who performs the reporting.
upvoted 1 times
TurboMor
8 months, 1 week ago
Option B does specify at the end "to document specific reporting SLAs" meaning that the organization would establish clear responsibilities for the reporting activities. The question does not mention issues with not knowing which security incidents need external reporting. Also, PII data was breached, so researching federal laws and regulatory compliance is a must when there is confusion.
upvoted 2 times
...
...
...
braveheart22
Most Recent 2 months ago
Selected Answer: B
The best answer is: B. Researching federal laws, regulatory compliance requirements, and organizational policies to document specific reporting SLAs Explanation: The issue identified in the lessons learned review is confusion over who is responsible for external reporting and when it should be done. Different data breaches require different reporting timelines based on laws such as GDPR, CCPA, and HIPAA, as well as industry regulations. By researching and documenting specific reporting SLAs (Service Level Agreements), the organization ensures clarity on reporting timelines and responsibilities in compliance with legal and regulatory requirements.
upvoted 1 times
...
fuzzyguzzy
5 months ago
Selected Answer: B
D seems to be the answer but the answer is B. The issue is understanding "who was responsible" and what the timing requirements are. You get this from laws, regulations, and SLAs. This helps determine what you do in D.
upvoted 1 times
...
fuzzyguzzy
5 months ago
D seems to be the answer but the answer is B. The issue is understanding "who was responsible" and what the timing requirements are. You get this from laws, regulations, and SLAs. This helps determine what you do in D.
upvoted 1 times
...
cy_analyst
7 months ago
Selected Answer: D
D is the best choice, as it directly addresses the core problem of unclear responsibilities and reporting timing during a data breach.
upvoted 1 times
cy_analyst
6 months, 3 weeks ago
B is the best answer: D is a quick fix but doesn't foster real learning. A is great if the company already has foundational knowledge. B is ideal for a less mature organization that needs to learn the fundamentals to build a solid foundation for future incident response.
upvoted 1 times
...
...
kinny4000
7 months ago
Selected Answer: A
A playbook would solve all problems, the confusion about who is to make the report and also the timings. Every other answer only addresses 1 part of the question.
upvoted 1 times
...
gomet2000
8 months, 3 weeks ago
Selected Answer: B
I asked Chatgpt what is discussed here: Which is the best option? **If the issue identified during the lessons learned review is primarily about understanding what needs to be reported and when according to legal or regulatory requirements, then B would indeed be the most appropriate action. It ensures that the organization has a clear, documented understanding of reporting obligations, which can then be communicated to those responsible. **If the issue is more about internal confusion over who should be doing the reporting and the timing within the organization, D would be the best choice to ensure clear assignment of responsibilities. Given the context of your question: If the discrepancies in the review were related to understanding external reporting requirements (e.g., legal timelines, specific regulatory obligations), then B would indeed be the most appropriate action to take.
upvoted 2 times
...
JAlexander35
9 months, 1 week ago
C and D both make sense here
upvoted 1 times
...
Chiniwini
9 months, 2 weeks ago
Selected Answer: D
Designating specific roles and responsibilities ensures that there is no ambiguity about who needs to take action during an incident. This clarity is essential for efficient and effective incident response, particularly for tasks like external reporting, which are time-sensitive and have significant compliance implications. Once roles and responsibilities are clearly defined, they can be integrated into playbooks and other procedural documents to ensure a comprehensive approach.
upvoted 2 times
Jay2021aws
8 months ago
Your answer does not address the sla issue
upvoted 1 times
...
...
maggie22
10 months, 1 week ago
Selected Answer: C
Option C is the most effective action because it directly resolves the identified issue by providing clarity on when and how external notifications and incident reporting should occur. This proactive approach helps strengthen the organization's incident response capabilities and compliance posture
upvoted 3 times
maggie22
8 months ago
after an in-depth researched and reading, I will change my answer with B.
upvoted 2 times
...
Chiniwini
9 months, 2 weeks ago
This is important for understanding what needs to be reported, but it does not address who is responsible for the reporting. Defining the scope of reporting is part of the solution but not sufficient on its own.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago