CompTIA CySA+ (CS0-001) — Question 197
Which of the following principles describes how a security analyst should communicate during an incident?
Answer options
- A. The communication should be limited to trusted parties only.
- B. The communication should be limited to security staff only.
- C. The communication should come from law enforcement.
- D. The communication should be limited to management only.
Correct answer: A
Explanation
The correct answer, A, emphasizes the importance of sharing information only with trusted individuals to prevent leaks and misinformation during an incident. Options B, C, and D are incorrect as they unnecessarily limit communication to specific groups, which could hinder the incident response process and exclude other necessary stakeholders.