Worth 16% of the CompTIA CySA+ (CS0-004) exam. CertClue has 49 questions on this objective.
What this objective covers
Reporting Incidents to Technical and Executive Audiences
The same incident needs to be described differently depending on who is reading the report. Analysts who write one version for every audience usually end up with a report that satisfies neither the executives who need a decision nor the engineers who need to act.
Exam tip. When a question asks what belongs in an executive summary versus a technical appendix, business impact and next steps go in the summary, technical detail goes in the appendix.
Practice questions
Free, with the answer and the reasoning. No account needed.
1. Junction Rail, a company operating in the European Union, confirms a data breach involving personal data of EU residents on a Monday morning. Under the General Data Protection Regulation, what is the maximum time frame within which the organization must generally notify the relevant supervisory authority, absent an applicable exemption?
A. 30 calendar days from confirmation of the breach
B. 90 calendar days from confirmation of the breach
C. There is no defined notification deadline under GDPR, only a general requirement to notify without undue delay
D. 72 hours from becoming aware of the breachcorrect
GDPR generally requires notifying the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in risk to individuals. 30 days, 90 days, and the claim that there is no defined deadline all misstate this requirement.
2. Fallowmere Trust's SOC is two hours into an active incident investigation and still confirming the full scope of affected systems. The CISO must brief the executive team before all facts are confirmed. Which approach best balances the need to inform leadership promptly with the risk of reporting inaccurate information?
A. Wait until the investigation is fully closed before saying anything to executives, to avoid reporting anything that later turns out to be wrong
B. Share what is confirmed so far, clearly separate it from what is still under investigation, and commit to a specific time for the next updatecorrect
C. Report the worst-case scope as if it were confirmed, so leadership is not caught off guard if it turns out to be that bad
D. Delegate the briefing entirely to a junior analyst so the CISO is not personally accountable if early details change
Communicating during an active incident means giving leadership an accurate, honest picture of what is known now, clearly flagging what remains unconfirmed, and setting an expectation for when more detail will follow, which keeps decision-makers informed without overstating certainty. Withholding all information until the investigation fully closes leaves leadership blind during the window they may most need to act, presenting an unconfirmed worst case as fact risks a credibility-damaging correction later, and delegating the briefing to avoid accountability does not address the actual communication problem.
Work the whole objective
The full CompTIA CySA+ bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.