Triage BoardGet the app

Domain 4 · Reporting and Communication

Incident reporting and communication

Incident reporting and communication, objective 4.2 of CS0-004, covers what gets said about an incident, by whom and to whom: declaring and escalating it, the communication plan for legal, public relations, regulators, law enforcement and customers, shift handovers, the after-action report, and the security operations center (SOC) metrics leadership reads (CS0-004 objectives, version 2.0, checked October 2026).

  • Exam code CS0-004
  • Domain weight 16%
  • Tickets here 18

The reports an incident produces

  1. Hour 0

    Declaration

    An analyst moves an event to an incident using the criteria in the incident response (IR) plan and records the time, the reason and the starting severity.

  2. Hour 1

    Escalation

    The severity triggers the escalation path the plan names. Each hand-up is logged with who was told and when.

  3. Hour 8

    Shift handover

    The outgoing analyst briefs the next shift on what is known, what is contained and what is still open, in writing as well as aloud.

  4. Day 2

    Executive summary

    A short, plain-language update for leadership. What goes in it, and what stays in the technical report, is on executive summary vs technical report.

  5. Day 3

    Internal threat intelligence report

    Indicators and attacker behavior from this incident go to the SOC and the hunt team, so detections and threat hunting can use them.

  6. Week 2

    After-action report

    The full timeline, the root cause, what worked and what did not, and the corrective actions agreed in the lessons-learned meeting.

  7. Quarter end

    Metrics review

    Detection, response and closure times, alert volume and accuracy, reported as trends across several quarters.

Who the communication plan covers

Stakeholders CS0-004 names in 4.2, and what each needs from the response team
StakeholderWhat they needTypical voiceWhat to keep out
LeadershipBusiness impact, decisions only they can makeIncident leadJargon and raw indicators
Legal teamFacts to judge contractual and statutory dutiesIncident leadGuesses stated as fact
Public relationsAn agreed statement and what cannot be said yetCommunications teamDetails that tip off the attacker
Regulatory agenciesA notice in the form and time the rule requiresLegal or complianceAnything the rule does not ask for
Law enforcementEvidence with its chain of custodyLegal, with the incident leadEvidence with gaps in custody
CustomersWhat happened to their data and what to do nowCommunications teamPromises the facts cannot support yet
Technical teamsTasks, indicators, the current timelineSOC or incident leadTasks with no owner

Who speaks for the organization is fixed in the communication plan before an incident starts.

How the exam tests each part

Declaration and escalation

Declaring an incident starts clocks: internal response targets, and in many cases legal deadlines. Escalation follows the written criteria in the IR plan, and each level the plan names is used in order.

Communication plan and operational security

The plan has to fit the organization: its regulators, its customers, its contracts. CS0-004 pairs it with operational security awareness, meaning you assume an attacker inside the network may read what the response team writes, and you choose channels with that in mind.

Post-incident reporting

Three terms, three jobs. The after-action report is the document. Lessons learned are the conclusions, reached in a meeting with everyone who worked the incident. Root cause analysis (RCA) is the method that finds why the incident was possible. A stem that asks what to produce wants the report; one that asks what to find wants the RCA.

Handover and internal intelligence

A shift handover is a security control: a fact that does not cross the handover is lost for eight hours. The internal threat intelligence report turns one incident into detection content for the next one. The vulnerability side of reporting, with its own audiences and metrics, is objective 4.1 on vulnerability reporting.

Metrics

Metric items ask which number answers a manager's question. Did detection get faster? Mean time to detect. Does the team act quickly once it knows? Mean time to respond. Do fixes land? Mean time to remediate. Read the false-positive rate together with the true-positive rate: a false-positive rate near zero can mean the rules were tuned until they stopped catching real activity.

The SOC metrics CS0-004 lists

Alert volume
How many alerts the SOC receives in a period. It measures workload; on its own it says nothing about risk.
False-positive rate
The share of alerts that turned out to be benign. High values point to rules that need tuning.
True-positive rate
The share of real malicious activity the detections caught. It falls when tuning goes too far.
Mean time to detect (MTTD)
Average time from the start of malicious activity to its detection.
Mean time to respond
Average time from detection to the first response action.
Mean time to remediate
Average time from detection to the fix being in place. Shares the acronym MTTR with respond, so spell it out.
Mean time to close
Average time from opening an incident or ticket to closing it. Compared side by side on MTTD vs MTTR vs MTTC.
Phishing campaign click rate
The share of users who clicked in a simulated phishing campaign. It tracks user awareness and says nothing about detection.

Who do you tell, and when?

Expect to decide who hears about an incident, how soon and in what terms, from the first escalation to the quarterly metrics review.

Ticket 1 / 18

0 right

INC-001

During a security breach, which department should be consulted first before communicating with external stakeholders?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ACompliance checks adherence to policies and regulations, but the decision about what can be said externally and what liability it creates belongs to legal counsel.
  2. BHuman Resources handles personnel and disciplinary matters, not the legal exposure of external statements.
  3. CCorrect: Legal should review first because external statements can create liability, affect regulatory notification duties, and touch privileged investigation details.
  4. DIT Support fixes technical problems; it has no role in approving what the organization tells outsiders.

INC-002

During a security incident, which communication channel should be used if the primary email system is potentially compromised?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AAn internal messaging system may share the same identity provider or infrastructure as the compromised email, so the attacker could still be watching.
  2. BCorrect: An out-of-band channel runs separately from the possibly compromised systems, so responders can coordinate without the attacker seeing their plans.
  3. CCompany social media is public and is the wrong place for confidential incident coordination.
  4. DUsing the compromised email system lets the attacker read the response plan as it is being made.

INC-003

Which external party should be contacted when a security incident involves a potential crime like data theft?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ASoftware vendors may help with a product flaw, but they cannot investigate a crime.
  2. BCorrect: Law enforcement has the authority to investigate criminal acts such as data theft and can advise on evidence handling for possible prosecution.
  3. CIndustry analysts study markets; telling them about a live incident would be an uncontrolled disclosure.
  4. DCompetitors have no role in the response, and telling them would leak sensitive information.

INC-004

An incident response team discovers a critical server breach. The technical lead insists on keeping the incident secret from business stakeholders until the vulnerability is fully patched. Why does this approach violate standard playbooks?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AKeeping the incident quiet does not speed up eradication; the problem is a communication failure, not skipped root-cause analysis.
  2. BPlaybooks do not require public relations for every incident, and stakeholder notification is about internal decision-makers instead of outside PR.
  3. CCorrect: Playbooks require timely escalation to business stakeholders during the incident so leaders can make risk decisions; waiting until patching is finished breaks that requirement.
  4. DSecrecy has nothing to do with choosing between forensic preservation and containment; the issue is withholding information from stakeholders.

INC-005

During an active investigation into a suspected widespread Business Email Compromise incident, the response team must coordinate immediate containment actions. Which communication approach minimizes operational risk while preserving chain-of-custody?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AIn a Business Email Compromise the corporate email system is the compromised channel, so even encrypted messages there can reveal the response to the attacker.
  2. BCorrect: An approved out-of-band secure messaging app keeps the attacker from watching containment plans and still keeps an auditable organizational record of communications.
  3. CNew personal webmail accounts are unmanaged and outside the organization's records, so they break chain-of-custody and governance.
  4. DUnencrypted SMS on personal devices is insecure and creates no reliable organizational record.

INC-006

During an active incident involving the compromise of a global administrator account, why is using the standard enterprise ticketing system for internal communication a significant operational risk?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. APersonal unapproved email is not a better option; it lacks governance and record-keeping and does not address the attacker's access.
  2. BWhether a ticketing tool accepts forensic images is a minor tooling detail and far from the operational risk in this scenario.
  3. CCorrect: A global administrator account can usually read enterprise tools, so the attacker may watch the ticketing system and see containment plans before they happen.
  4. DTicketing systems do not automatically lock out responders; the risk is that the attacker can see what they write there.

INC-007

Based on the incident timeline, which sequence correctly orders the engagement of external entities before issuing a public press release about a confirmed data breach?

Exhibit

TimeIncident EventAction Required
08:00Breach ConfirmedInternal Escalation
09:00Media InquiriesPrepare Statement
10:00Containment MetExternal Briefing

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AIssuing a press release first, before legal review, risks inaccurate or damaging statements and conflicts with notification requirements.
  2. BA press release should never come before legal review, and contacting law enforcement first without counsel skips coordination.
  3. CNotifying customers before consulting counsel puts legal review last, when it should shape every external message.
  4. DCorrect: Counsel is consulted first, PR then prepares a reviewed statement, and regulators are notified as the law requires, all before a public press release.

INC-008

An analyst identifies a malware infection on an isolated development workstation. Review the severity matrix. What is the correct escalation path for this incident?

Exhibit

Severity LevelDescriptionEscalation Path
HighCritical business system compromiseNotify C-Suite and Legal
MediumNon-critical system with sensitive dataNotify IT Director
LowIsolated system with no sensitive dataNotify local SOC supervisor

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AHigh severity is for compromise of critical business systems; an isolated development workstation without sensitive data does not meet that bar.
  2. BCorrect: An isolated system with no sensitive data matches the Low row of the matrix, so the escalation path is the local SOC supervisor.
  3. CMedium severity requires a non-critical system that holds sensitive data, and nothing in the scenario says the workstation holds any.
  4. DThis over-escalates and also uses an escalation path that is not in the matrix.

INC-009

A reconstructed timeline shows recon through exfiltration. Which threshold should trigger executive escalation?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ADiscovery commands on one workstation are early, low-confidence activity that the SOC can handle without executives.
  2. BA single failed logon is routine noise and would flood executives with false alarms.
  3. CCorrect: Confirmed persistence plus data staging shows the attacker is established and preparing to exfiltrate, which is the kind of imminent business impact that warrants executive escalation.
  4. DOne DNS query to a known domain is a single indicator that needs triage and falls well below an executive-level threshold.

INC-010

An IR policy states escalation occurs for any incident with potential regulatory impact. Which replacement criteria make thresholds measurable and actionable?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Measurable criteria such as data volume and number of affected assets let analysts apply escalation the same way every time, instead of guessing what might be regulatory.
  2. BQualitative descriptions alone keep the ambiguity the policy is trying to remove.
  3. CEscalating every malware detection to executives creates alert fatigue and ignores actual impact.
  4. DEscalating based on a manager's feeling is subjective and cannot be applied consistently.

INC-011

A junior analyst redacted a security log before sending it to an incident response firm. The receiving firm states they cannot perform timeline analysis or link related events. Which over-redaction mistake most likely occurred?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Timestamps and session correlation IDs are what let analysts order events and link related activity, so masking them makes timeline analysis impossible.
  2. BTruncated payload strings limit analysis of the exploit itself but do not stop the firm from ordering and linking events.
  3. CGeneric tags in place of hostnames still let events be linked as long as each tag is used consistently.
  4. DConsistent random tokens hide user identities but still let related events be linked to the same account.

INC-012

A third-party vendor requires database logs to track anomalous user behavior. Which tokenized output correctly protects personally identifiable information while preserving the relational data structure?

Exhibit

Raw Log IdentifierDatabase EventTransaction
John.Doe_SSN:1234Login SuccessTx_9912
John.Doe_SSN:1234Data ExportTx_9913
Jane.Smith_Acct:88File UploadTx_9914

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Consistent tokens hide the identities but keep the link that the same user did both the login and the export, which behavioral analysis needs.
  2. BReplacing every identifier with the same null value protects privacy but destroys the ability to link actions to a user.
  3. CGiving the same person two different tokens breaks the relationship between the login and the export.
  4. DKeeping real names exposes personal information to the vendor.

INC-013

A company decides to wait for the final root-cause analysis before issuing statutorily required notifications. Based on the provided timeline, what is the primary risk of this approach?

Exhibit

MilestoneStatusDate
Initial DiscoveryConfirmedJune 1
ContainmentCompletedJune 5
Root-Cause AnalysisPendingExpected August 15
Statutory DeadlineN/A60 days post-discovery

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AContainment is already finished; a longer root-cause analysis does not undo it.
  2. BNotification laws do not require releasing plaintext copies of exposed records.
  3. CEvidence preservation is a separate duty and does not depend on when notifications are sent.
  4. DCorrect: The 60-day clock starts at discovery on June 1, so waiting for a root-cause analysis due August 15 misses the deadline.

INC-014

An organization experiences a breach triggering reporting obligations under three different regulatory frameworks with conflicting timelines and content requirements. Which approach should the incident response team take when preparing notifications?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AFollowing the most lenient timeline violates the stricter frameworks that also apply.
  2. BStaggered, inconsistent notices can still miss the strictest deadline and create conflicting public statements.
  3. CCorrect: Writing notices that meet the strictest timing and content requirements satisfies every framework at once and keeps the messages consistent.
  4. DRegulators do not require plaintext samples of exposed records, and including them would cause more exposure.

INC-015

Which elements should an action register include to enforce closure of post-incident lessons learned?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AA timeline records what happened but does not track whether fixes are completed.
  2. BNotes without deadlines or validation give no way to enforce or confirm closure.
  3. CCorrect: Each action item needs an owner, a deadline, and regular status updates so lessons learned turn into completed fixes.
  4. DA list of gaps without owners leaves no one accountable, so items tend to stay open.

INC-016

A SOC dashboard shows a 99 percent alert closure rate for the current quarter. Which scenario demonstrates why this metric might mislead stakeholders regarding actual organizational risk?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ASkipping peer review on informational alerts is a quality problem, but those alerts carry little risk, so it does not show why the metric hides real risk.
  2. BMore false positives inflate the workload but would usually make closure easier, so they would not hide open high-risk items.
  3. CCorrect: If the 1 percent left open are all critical alerts, a 99 percent closure rate looks excellent while the most dangerous issues remain unresolved.
  4. DAutomating routine malware remediation is a legitimate efficiency gain and no sign the metric is misleading.

INC-017

A weekly report highlights a 40 percent increase in total raw alerts compared to the previous week. Which missing piece of context most likely renders this statistic misleading?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AMean time to detect measures speed and cannot explain why the raw number of alerts changed.
  2. BATT&CK categories describe what kind of alerts fired but do not explain an overall increase in volume.
  3. CCorrect: If many new assets were added, more alerts are expected, so raw counts must be normalized, for example alerts per 1,000 assets, before they mean anything.
  4. DTime to contain is a response metric and does not explain why alert volume grew.

INC-018

When structuring a one-page executive briefing, which specific sequence properly organizes the required information for leadership consumption?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Executives need the business impact first, then scope and risk, the decisions or actions asked of them, and current status, without technical detail.
  2. BTechnical root cause and endpoint lists are too detailed for leadership, and budget out of context does not tell them what is at stake.
  3. CExploit mechanics and team schedules are operational details that do not belong on a one-page executive brief.
  4. DRaw event logs and network maps are technical artifacts that executives cannot use to make decisions.

Shift tally

0 / 0

A shift handover that loses nothing

  • Open incidents with current severity and the next action on each.
  • What is contained and what is not, and on which hosts or accounts.
  • Indicators still being watched, and where the alerts for them land.
  • Who is waiting on whom: legal, a vendor, a system owner.
  • Deadlines running, internal or external, with the time each started.
  • Where the timeline and the evidence log are kept.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.