Objective 4.2CS0-003

4.2 Explain the importance of incident response reporting and communication.

Objective 4.2 sits in Reporting and Communication, which carries 17% of the CySA+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

4-2Reporting and CommunicationModerate

A federal agency's SOC confirms a compromise of a production system. Under the notification guidelines, how quickly must the team report it to CISA?

Within 24 hours of containmentContainment status does not start or stop the reporting clock.
Within one hour of identificationCorrect · your answerCorrect: one hour from identification by the CSIRT, SOC, or IT department.
Within 72 hours of eradicationThe 72-hour figure belongs to other regimes, not these guidelines.
At the next quarterly FISMA filingAnnual FISMA reporting is separate from incident notification.

Correct.

Concept

Regulatory reporting clocks start at identification, not resolution. Early notification trades completeness for situational awareness, on the theory that partial information now beats full information late.

Why B

Incidents potentially compromising confidentiality, integrity, or availability must be reported with the required data elements within one hour of being identified by the agency's top-level CSIRT, SOC, or IT department.

#regulatory-reporting#escalation#incident-reporting

Now you: objective 4.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

4-2Reporting and CommunicationModerate

An analyst delays a required notification because several data elements are still unconfirmed. What do the guidelines say to do instead?

Sample question 2 of 3

4-2Reporting and CommunicationHard

A responder argues the team cannot notify CISA until root cause is established. Why do the guidelines disagree?

Sample question 3 of 3

4-2Reporting and CommunicationModerate

A team debates whether a policy violation with no data loss counts as an incident. How does FISMA define one?

Full CySA+ question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Reporting and Communication