nerdexam
CompTIA

CS0-003 · Question #94

An incident response team detected malicious software that could have gained access to credit card data. The incident response team was able to mitigate significant damage and implement corrective act

The correct answer is C. Company leadership. Following an incident where malicious software accessed credit card data, the incident response team should notify company leadership for lessons learned after mitigating damage and implementing corrective actions.

Submitted by carlos_mx· Mar 6, 2026Incident Response and Management

Question

An incident response team detected malicious software that could have gained access to credit card data. The incident response team was able to mitigate significant damage and implement corrective actions. By having incident response mechanisms in place. Which of the following should be notified for lessons learned?

Options

  • AThe human resources department
  • BCustomers
  • CCompany leadership
  • DThe legal team

How the community answered

(20 responses)
  • A
    5% (1)
  • C
    90% (18)
  • D
    5% (1)

Why each option

Following an incident where malicious software accessed credit card data, the incident response team should notify company leadership for lessons learned after mitigating damage and implementing corrective actions.

AThe human resources department

The human resources department is typically involved in personnel-related matters, not directly in reviewing technical lessons learned from an incident response.

BCustomers

Customers might require notification about a data breach, but they are not involved in internal 'lessons learned' discussions about incident response processes.

CCompany leadershipCorrect

Company leadership is the primary audience for lessons learned from significant security incidents, as they need to understand the impact, evaluate incident response effectiveness, and make strategic decisions for future security improvements and resource allocation.

DThe legal team

The legal team addresses compliance and potential legal ramifications, but they are not the central body for reviewing operational 'lessons learned' regarding security posture improvement.

Concept tested: Post-incident review and communication

Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final

Topics

#Incident response process#Lessons learned#Stakeholder communication

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice