Incident reporting and communication, objective 4.2 of CS0-004, covers what gets said about an incident, by whom and to whom: declaring and escalating it, the communication plan for legal, public relations, regulators, law enforcement and customers, shift handovers, the after-action report, and the security operations center (SOC) metrics leadership reads (CS0-004 objectives, version 2.0, checked October 2026).
Exam code CS0-004
Domain weight 16%
Tickets here 18
01The reports an incident produces
Hour 0
Declaration
An analyst moves an event to an incident using the criteria in the incident response (IR) plan and records the time, the reason and the starting severity.
Hour 1
Escalation
The severity triggers the escalation path the plan names. Each hand-up is logged with who was told and when.
Hour 8
Shift handover
The outgoing analyst briefs the next shift on what is known, what is contained and what is still open, in writing as well as aloud.
Day 2
Executive summary
A short, plain-language update for leadership. What goes in it, and what stays in the technical report, is on executive summary vs technical report.
Day 3
Internal threat intelligence report
Indicators and attacker behavior from this incident go to the SOC and the hunt team, so detections and threat hunting can use them.
Week 2
After-action report
The full timeline, the root cause, what worked and what did not, and the corrective actions agreed in the lessons-learned meeting.
Quarter end
Metrics review
Detection, response and closure times, alert volume and accuracy, reported as trends across several quarters.
02Who the communication plan covers
Stakeholders CS0-004 names in 4.2, and what each needs from the response teamscroll →
Stakeholder
What they need
Typical voice
What to keep out
Leadership
Business impact, decisions only they can make
Incident lead
Jargon and raw indicators
Legal team
Facts to judge contractual and statutory duties
Incident lead
Guesses stated as fact
Public relations
An agreed statement and what cannot be said yet
Communications team
Details that tip off the attacker
Regulatory agencies
A notice in the form and time the rule requires
Legal or compliance
Anything the rule does not ask for
Law enforcement
Evidence with its chain of custody
Legal, with the incident lead
Evidence with gaps in custody
Customers
What happened to their data and what to do now
Communications team
Promises the facts cannot support yet
Technical teams
Tasks, indicators, the current timeline
SOC or incident lead
Tasks with no owner
Who speaks for the organization is fixed in the communication plan before an incident starts.
03How the exam tests each part
Declaration and escalation
Declaring an incident starts clocks: internal response targets, and in many cases legal deadlines. Escalation follows the written criteria in the IR plan, and each level the plan names is used in order.
Communication plan and operational security
The plan has to fit the organization: its regulators, its customers, its contracts. CS0-004 pairs it with operational security awareness, meaning you assume an attacker inside the network may read what the response team writes, and you choose channels with that in mind.
Post-incident reporting
Three terms, three jobs. The after-action report is the document. Lessons learned are the conclusions, reached in a meeting with everyone who worked the incident. Root cause analysis (RCA) is the method that finds why the incident was possible. A stem that asks what to produce wants the report; one that asks what to find wants the RCA.
Handover and internal intelligence
A shift handover is a security control: a fact that does not cross the handover is lost for eight hours. The internal threat intelligence report turns one incident into detection content for the next one. The vulnerability side of reporting, with its own audiences and metrics, is objective 4.1 on vulnerability reporting.
Metrics
Metric items ask which number answers a manager's question. Did detection get faster? Mean time to detect. Does the team act quickly once it knows? Mean time to respond. Do fixes land? Mean time to remediate. Read the false-positive rate together with the true-positive rate: a false-positive rate near zero can mean the rules were tuned until they stopped catching real activity.
04The SOC metrics CS0-004 lists
Alert volume
How many alerts the SOC receives in a period. It measures workload; on its own it says nothing about risk.
False-positive rate
The share of alerts that turned out to be benign. High values point to rules that need tuning.
True-positive rate
The share of real malicious activity the detections caught. It falls when tuning goes too far.
Mean time to detect (MTTD)
Average time from the start of malicious activity to its detection.
Mean time to respond
Average time from detection to the first response action.
Mean time to remediate
Average time from detection to the fix being in place. Shares the acronym MTTR with respond, so spell it out.
Mean time to close
Average time from opening an incident or ticket to closing it. Compared side by side on MTTD vs MTTR vs MTTC.
Phishing campaign click rate
The share of users who clicked in a simulated phishing campaign. It tracks user awareness and says nothing about detection.
05Who do you tell, and when?
Expect to decide who hears about an incident, how soon and in what terms, from the first escalation to the quarterly metrics review.
Ticket 1 / 18
0 right
INC-001
During a security breach, which department should be consulted first before communicating with external stakeholders?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
ACompliance checks adherence to policies and regulations, but the decision about what can be said externally and what liability it creates belongs to legal counsel.
BHuman Resources handles personnel and disciplinary matters, not the legal exposure of external statements.
CCorrect: Legal should review first because external statements can create liability, affect regulatory notification duties, and touch privileged investigation details.
DIT Support fixes technical problems; it has no role in approving what the organization tells outsiders.
INC-002
During a security incident, which communication channel should be used if the primary email system is potentially compromised?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: B
AAn internal messaging system may share the same identity provider or infrastructure as the compromised email, so the attacker could still be watching.
BCorrect: An out-of-band channel runs separately from the possibly compromised systems, so responders can coordinate without the attacker seeing their plans.
CCompany social media is public and is the wrong place for confidential incident coordination.
DUsing the compromised email system lets the attacker read the response plan as it is being made.
INC-003
Which external party should be contacted when a security incident involves a potential crime like data theft?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: B
ASoftware vendors may help with a product flaw, but they cannot investigate a crime.
BCorrect: Law enforcement has the authority to investigate criminal acts such as data theft and can advise on evidence handling for possible prosecution.
CIndustry analysts study markets; telling them about a live incident would be an uncontrolled disclosure.
DCompetitors have no role in the response, and telling them would leak sensitive information.
INC-004
An incident response team discovers a critical server breach. The technical lead insists on keeping the incident secret from business stakeholders until the vulnerability is fully patched. Why does this approach violate standard playbooks?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
AKeeping the incident quiet does not speed up eradication; the problem is a communication failure, not skipped root-cause analysis.
BPlaybooks do not require public relations for every incident, and stakeholder notification is about internal decision-makers instead of outside PR.
CCorrect: Playbooks require timely escalation to business stakeholders during the incident so leaders can make risk decisions; waiting until patching is finished breaks that requirement.
DSecrecy has nothing to do with choosing between forensic preservation and containment; the issue is withholding information from stakeholders.
INC-005
During an active investigation into a suspected widespread Business Email Compromise incident, the response team must coordinate immediate containment actions. Which communication approach minimizes operational risk while preserving chain-of-custody?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: B
AIn a Business Email Compromise the corporate email system is the compromised channel, so even encrypted messages there can reveal the response to the attacker.
BCorrect: An approved out-of-band secure messaging app keeps the attacker from watching containment plans and still keeps an auditable organizational record of communications.
CNew personal webmail accounts are unmanaged and outside the organization's records, so they break chain-of-custody and governance.
DUnencrypted SMS on personal devices is insecure and creates no reliable organizational record.
INC-006
During an active incident involving the compromise of a global administrator account, why is using the standard enterprise ticketing system for internal communication a significant operational risk?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
APersonal unapproved email is not a better option; it lacks governance and record-keeping and does not address the attacker's access.
BWhether a ticketing tool accepts forensic images is a minor tooling detail and far from the operational risk in this scenario.
CCorrect: A global administrator account can usually read enterprise tools, so the attacker may watch the ticketing system and see containment plans before they happen.
DTicketing systems do not automatically lock out responders; the risk is that the attacker can see what they write there.
INC-007
Based on the incident timeline, which sequence correctly orders the engagement of external entities before issuing a public press release about a confirmed data breach?
Exhibitscroll →
Time
Incident Event
Action Required
08:00
Breach Confirmed
Internal Escalation
09:00
Media Inquiries
Prepare Statement
10:00
Containment Met
External Briefing
Pick an option to open the notes on all of them.
Key and notes on every option
Key: D
AIssuing a press release first, before legal review, risks inaccurate or damaging statements and conflicts with notification requirements.
BA press release should never come before legal review, and contacting law enforcement first without counsel skips coordination.
CNotifying customers before consulting counsel puts legal review last, when it should shape every external message.
DCorrect: Counsel is consulted first, PR then prepares a reviewed statement, and regulators are notified as the law requires, all before a public press release.
INC-008
An analyst identifies a malware infection on an isolated development workstation. Review the severity matrix. What is the correct escalation path for this incident?
Exhibitscroll →
Severity Level
Description
Escalation Path
High
Critical business system compromise
Notify C-Suite and Legal
Medium
Non-critical system with sensitive data
Notify IT Director
Low
Isolated system with no sensitive data
Notify local SOC supervisor
Pick an option to open the notes on all of them.
Key and notes on every option
Key: B
AHigh severity is for compromise of critical business systems; an isolated development workstation without sensitive data does not meet that bar.
BCorrect: An isolated system with no sensitive data matches the Low row of the matrix, so the escalation path is the local SOC supervisor.
CMedium severity requires a non-critical system that holds sensitive data, and nothing in the scenario says the workstation holds any.
DThis over-escalates and also uses an escalation path that is not in the matrix.
INC-009
A reconstructed timeline shows recon through exfiltration. Which threshold should trigger executive escalation?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
ADiscovery commands on one workstation are early, low-confidence activity that the SOC can handle without executives.
BA single failed logon is routine noise and would flood executives with false alarms.
CCorrect: Confirmed persistence plus data staging shows the attacker is established and preparing to exfiltrate, which is the kind of imminent business impact that warrants executive escalation.
DOne DNS query to a known domain is a single indicator that needs triage and falls well below an executive-level threshold.
INC-010
An IR policy states escalation occurs for any incident with potential regulatory impact. Which replacement criteria make thresholds measurable and actionable?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
ACorrect: Measurable criteria such as data volume and number of affected assets let analysts apply escalation the same way every time, instead of guessing what might be regulatory.
BQualitative descriptions alone keep the ambiguity the policy is trying to remove.
CEscalating every malware detection to executives creates alert fatigue and ignores actual impact.
DEscalating based on a manager's feeling is subjective and cannot be applied consistently.
INC-011
A junior analyst redacted a security log before sending it to an incident response firm. The receiving firm states they cannot perform timeline analysis or link related events. Which over-redaction mistake most likely occurred?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
ACorrect: Timestamps and session correlation IDs are what let analysts order events and link related activity, so masking them makes timeline analysis impossible.
BTruncated payload strings limit analysis of the exploit itself but do not stop the firm from ordering and linking events.
CGeneric tags in place of hostnames still let events be linked as long as each tag is used consistently.
DConsistent random tokens hide user identities but still let related events be linked to the same account.
INC-012
A third-party vendor requires database logs to track anomalous user behavior. Which tokenized output correctly protects personally identifiable information while preserving the relational data structure?
Exhibitscroll →
Raw Log Identifier
Database Event
Transaction
John.Doe_SSN:1234
Login Success
Tx_9912
John.Doe_SSN:1234
Data Export
Tx_9913
Jane.Smith_Acct:88
File Upload
Tx_9914
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
ACorrect: Consistent tokens hide the identities but keep the link that the same user did both the login and the export, which behavioral analysis needs.
BReplacing every identifier with the same null value protects privacy but destroys the ability to link actions to a user.
CGiving the same person two different tokens breaks the relationship between the login and the export.
DKeeping real names exposes personal information to the vendor.
INC-013
A company decides to wait for the final root-cause analysis before issuing statutorily required notifications. Based on the provided timeline, what is the primary risk of this approach?
Exhibitscroll →
Milestone
Status
Date
Initial Discovery
Confirmed
June 1
Containment
Completed
June 5
Root-Cause Analysis
Pending
Expected August 15
Statutory Deadline
N/A
60 days post-discovery
Pick an option to open the notes on all of them.
Key and notes on every option
Key: D
AContainment is already finished; a longer root-cause analysis does not undo it.
BNotification laws do not require releasing plaintext copies of exposed records.
CEvidence preservation is a separate duty and does not depend on when notifications are sent.
DCorrect: The 60-day clock starts at discovery on June 1, so waiting for a root-cause analysis due August 15 misses the deadline.
INC-014
An organization experiences a breach triggering reporting obligations under three different regulatory frameworks with conflicting timelines and content requirements. Which approach should the incident response team take when preparing notifications?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
AFollowing the most lenient timeline violates the stricter frameworks that also apply.
BStaggered, inconsistent notices can still miss the strictest deadline and create conflicting public statements.
CCorrect: Writing notices that meet the strictest timing and content requirements satisfies every framework at once and keeps the messages consistent.
DRegulators do not require plaintext samples of exposed records, and including them would cause more exposure.
INC-015
Which elements should an action register include to enforce closure of post-incident lessons learned?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
AA timeline records what happened but does not track whether fixes are completed.
BNotes without deadlines or validation give no way to enforce or confirm closure.
CCorrect: Each action item needs an owner, a deadline, and regular status updates so lessons learned turn into completed fixes.
DA list of gaps without owners leaves no one accountable, so items tend to stay open.
INC-016
A SOC dashboard shows a 99 percent alert closure rate for the current quarter. Which scenario demonstrates why this metric might mislead stakeholders regarding actual organizational risk?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
ASkipping peer review on informational alerts is a quality problem, but those alerts carry little risk, so it does not show why the metric hides real risk.
BMore false positives inflate the workload but would usually make closure easier, so they would not hide open high-risk items.
CCorrect: If the 1 percent left open are all critical alerts, a 99 percent closure rate looks excellent while the most dangerous issues remain unresolved.
DAutomating routine malware remediation is a legitimate efficiency gain and no sign the metric is misleading.
INC-017
A weekly report highlights a 40 percent increase in total raw alerts compared to the previous week. Which missing piece of context most likely renders this statistic misleading?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: C
AMean time to detect measures speed and cannot explain why the raw number of alerts changed.
BATT&CK categories describe what kind of alerts fired but do not explain an overall increase in volume.
CCorrect: If many new assets were added, more alerts are expected, so raw counts must be normalized, for example alerts per 1,000 assets, before they mean anything.
DTime to contain is a response metric and does not explain why alert volume grew.
INC-018
When structuring a one-page executive briefing, which specific sequence properly organizes the required information for leadership consumption?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
ACorrect: Executives need the business impact first, then scope and risk, the decisions or actions asked of them, and current status, without technical detail.
BTechnical root cause and endpoint lists are too detailed for leadership, and budget out of context does not tell them what is at stake.
CExploit mechanics and team schedules are operational details that do not belong on a one-page executive brief.
DRaw event logs and network maps are technical artifacts that executives cannot use to make decisions.
Shift tally
0 / 0
06A shift handover that loses nothing
Open incidents with current severity and the next action on each.
What is contained and what is not, and on which hosts or accounts.
Indicators still being watched, and where the alerts for them land.
Who is waiting on whom: legal, a vendor, a system owner.
Deadlines running, internal or external, with the time each started.
Where the timeline and the evidence log are kept.
Keep the queue going on your phone
Our practice app carries CySA+ questions to your phone, on iPhone and Android.