CompTIA CySA+ (CS0-002) — Question 368
An analyst must review a new cloud-based SIEM solution. Which of the following should the analyst do FIRST prior to discussing the company's needs?
Answer options
- A. Check industry news feeds for product reviews.
- B. Ensure a current non-disclosure agreement is on file.
- C. Perform a vulnerability scan against a test instance.
- D. Download the product security white paper.
Correct answer: B
Explanation
The correct answer is B because having a signed non-disclosure agreement ensures that any sensitive company information discussed remains confidential. Options A, C, and D are not priorities since they do not secure the necessary confidentiality before engaging in discussions about the company's needs.