nerdexam
CompTIA

CS0-003 · Question #79

Which of the following are the MOST likely reasons lo include reporting processes when updating an incident response plan after a breach? (Select TWO).

The correct answer is A. To establish a clear chain of command B. To meet regulatory requirements for timely reporting. Including reporting processes in an incident response plan is critical for establishing a clear chain of command and meeting regulatory requirements for timely reporting.

Submitted by renata2k· Mar 6, 2026Reporting and Communication

Question

Which of the following are the MOST likely reasons lo include reporting processes when updating an incident response plan after a breach? (Select TWO).

Options

  • ATo establish a clear chain of command
  • BTo meet regulatory requirements for timely reporting
  • CTo limit reputation damage caused by the breach
  • DTo remediate vulnerabilities that led to the breach
  • ETo isolate potential insider threats
  • FTo provide secure network design changes

How the community answered

(24 responses)
  • A
    83% (20)
  • C
    4% (1)
  • D
    4% (1)
  • E
    8% (2)

Why each option

Including reporting processes in an incident response plan is critical for establishing a clear chain of command and meeting regulatory requirements for timely reporting.

ATo establish a clear chain of commandCorrect

Establishing a clear chain of command through defined reporting processes ensures that during a breach, there is a structured flow for who receives incident information, who makes critical decisions, and who is responsible for communicating updates, preventing confusion and enabling efficient response.

BTo meet regulatory requirements for timely reportingCorrect

Many industries and jurisdictions have strict regulatory requirements for timely reporting of security breaches to authorities, affected individuals, or other entities; including these processes in the IR plan ensures compliance and helps avoid legal penalties.

CTo limit reputation damage caused by the breach

While timely and appropriate reporting can help mitigate reputation damage, this is an outcome, not the primary reason to specifically *include* the reporting *process* in the plan, which focuses on compliance and orderly communication.

DTo remediate vulnerabilities that led to the breach

Remediating vulnerabilities is part of the containment and eradication phases of incident response, a distinct activity from the reporting processes that outline communication protocols.

ETo isolate potential insider threats

Isolating potential insider threats is a specific action taken during an incident, not a fundamental reason for the general inclusion of reporting processes within the plan.

FTo provide secure network design changes

Providing secure network design changes is part of the post-incident improvement and lessons learned phase, not directly a reason for including reporting processes within the incident response plan.

Concept tested: Incident response plan - reporting importance

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#Incident reporting#Regulatory compliance#Chain of command#Post-incident review

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice