exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 284 discussion

Actual exam question from CompTIA's CS0-002
Question #: 284
Topic #: 1
[All CS0-002 Questions]

An incident response team is responding to a breach of multiple systems that contain PII and PHI. Disclosure of the incident to external entities should be based on:

  • A. the responder's discretion.
  • B. the public relations policy.
  • C. the communication plan.
  • D. the senior management team's guidance.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
db97
2 years, 2 months ago
Selected Answer: C
https://www.examtopics.com/discussions/comptia/view/51782-exam-cs0-002-topic-1-question-134-discussion/
upvoted 2 times
2Fish
2 years, 1 month ago
Agree. Here is an example per your link: The incident response section (4.1) of the Comptia exam objectives is shown as the following: Communication plan - Limiting communication to trusted parties - Disclosing based on regulatory/ legislative requirements - Preventing inadvertent release of information - Using a secure method of communication - Reporting requirements C is the correct answer. B falls under the second bullet above.
upvoted 1 times
...
...
Cock
2 years, 2 months ago
Selected Answer: D
Disclosure of a security incident to external entities, especially one that involves sensitive data such as personally identifiable information (PII) and protected health information (PHI), should be based on the guidance of senior management. Senior management will assess the impact and potential fallout of the breach and determine the appropriate parties to notify, such as regulatory bodies and affected individuals. The communication plan and public relations policy should be informed by this guidance. The incident response team should work with senior management to ensure that appropriate notifications are made in a timely manner.
upvoted 2 times
...
encxorblood
2 years, 2 months ago
Selected Answer: C
The decision to disclose a data breach to external entities should be based on the organization's communication plan and the senior management team's guidance. The plan should include criteria for determining when an incident is reportable to regulators, customers, partners, or the public, as well as the appropriate channels for communicating the breach to these entities. The decision to disclose should be based on the severity of the breach, the sensitivity of the data that was compromised, and other relevant factors that may impact the organization's reputation or legal obligations. The incident response team should follow the communication plan and seek guidance from senior management in making decisions about when and how to disclose the breach.
upvoted 1 times
...
gnnggnnggnng
2 years, 3 months ago
Selected Answer: C
C. the communication plan. Disclosure of an incident that involves sensitive data, such as PII (personally identifiable information) and PHI (personal health information), should be based on the organization's communication plan. This plan outlines the steps that should be taken when communicating about incidents, including the timing, method, and audience for the communication. The plan ensures that the incident is communicated in a consistent, controlled manner that protects the interests of the organization and its stakeholders, such as customers and employees. The senior management team may provide guidance on the communication plan, but the actual decision on disclosure should be based on the plan itself.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago