nerdexam
CompTIA

CS0-003 · Question #58

Which of the following describes how a CSIRT lead determines who should be communicated with and when during a security incident?

The correct answer is A. The lead should review what is documented in the incident response policy or plan. The incident response policy or plan is a document that defines the roles and responsibilities, procedures and processes, communication and escalation protocols, and reporting and documentation requirements for handling security incidents. The lead should review what is…

Submitted by yaw92· Mar 6, 2026Incident Response and Management

Question

Which of the following describes how a CSIRT lead determines who should be communicated with and when during a security incident?

Options

  • AThe lead should review what is documented in the incident response policy or plan
  • BManagement level members of the CSIRT should make that decision
  • CThe lead has the authority to decide who to communicate with at any t me
  • DSubject matter experts on the team should communicate with others within the specified area of

How the community answered

(40 responses)
  • A
    93% (37)
  • C
    5% (2)
  • D
    3% (1)

Explanation

The incident response policy or plan is a document that defines the roles and responsibilities, procedures and processes, communication and escalation protocols, and reporting and documentation requirements for handling security incidents. The lead should review what is documented in the incident response policy or plan to determine who should be communicated with and when during a security incident, as well as what information should be shared and how. The incident response policy or plan should also be aligned with the organizational policies and legal obligations regarding incident notification and disclosure.

Topics

#incident communication#CSIRT#incident response policy

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice