CompTIA CySA+ (CS0-001) — Question 7

A security analyst is adding input to the incident response communication plan. A company officer has suggested that if a data breach occurs, only affected parties should be notified to keep an incident from becoming a media headline. Which of the following should the analyst recommend to the company officer?

Answer options

Correct answer: A

Explanation

The correct answer is A because contacting law enforcement ensures that a proper investigation can take place and that evidence is preserved, which is crucial in the event of a data breach. The other options, while relevant to incident response, do not directly address the immediate need to involve law enforcement and ensure proper handling of the incident.