nerdexam
CompTIA

CS0-003 · Question #340

An organization discovered a data breach that resulted in PII being released to the public. During the lessons learned review, the panel identified discrepancies regarding who was responsible for exte

The correct answer is B. Researching federal laws, regulatory compliance requirements, and organizational policies to. Researching federal laws, regulatory compliance requirements, and organizational policies to document specific reporting SLAs is the best action to address the reporting issue. Reporting SLAs are service level agreements that specify the time frame and the format for notifying th

Submitted by daniela_cl· Mar 6, 2026Reporting and Communication

Question

An organization discovered a data breach that resulted in PII being released to the public. During the lessons learned review, the panel identified discrepancies regarding who was responsible for external reporting, as well as the timing requirements. Which of the following actions would best address the reporting issue?

Options

  • ACreating a playbook denoting specific SLAs and containment actions per incident type
  • BResearching federal laws, regulatory compliance requirements, and organizational policies to
  • CDefining which security incidents require external notifications and incident reporting in addition to
  • DDesignating specific roles and responsibilities within the security team and stakeholders to

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    84% (21)
  • C
    8% (2)
  • D
    4% (1)

Explanation

Researching federal laws, regulatory compliance requirements, and organizational policies to document specific reporting SLAs is the best action to address the reporting issue. Reporting SLAs are service level agreements that specify the time frame and the format for notifying the relevant authorities and the affected individuals of a data breach. Reporting SLAs may vary depending on the type and severity of the breach, the type and location of the data, the industry and jurisdiction of the organization, and the internal policies of the organization. By researching and documenting the reporting SLAs for different scenarios, the organization can ensure that it complies with the legal and ethical obligations of data breach notification, and avoid any penalties, fines, or lawsuits that may result from failing to report a breach in a timely and appropriate manner.

Topics

#Data breach#External reporting#Regulatory compliance#Lessons learned

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice