CompTIA CySA+ (CS0-003) — Question 295
Which of the following responsibilities does the legal team have during an incident management event? (Choose two).
Answer options
- A. Coordinate additional or temporary staffing for recovery efforts.
- B. Review and approve new contracts acquired as a result of an event.
- C. Advise the incident response team on matters related to regulatory reporting.
- D. Ensure all system security devices and procedures are in place.
- E. Conduct computer and network damage assessments for insurance.
- F. Verify that all security personnel have the appropriate clearances.
Correct answer: B, C
Explanation
The correct answers are B and C because the legal team is responsible for reviewing contracts and advising on regulatory compliance during incidents. Options A, D, E, and F pertain to operational or security aspects, which typically fall under the responsibilities of IT or security teams rather than the legal team.