4.2 Explain the importance of incident response reporting and communication.
Objective 4.2 sits in Reporting and Communication, which carries 17% of the CySA+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.
Objective title verbatim from the official objectives. CompTIA exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A federal agency's SOC confirms a compromise of a production system. Under the notification guidelines, how quickly must the team report it to CISA?
Correct.
Concept
Regulatory reporting clocks start at identification, not resolution. Early notification trades completeness for situational awareness, on the theory that partial information now beats full information late.
Why B
Incidents potentially compromising confidentiality, integrity, or availability must be reported with the required data elements within one hour of being identified by the agency's top-level CSIRT, SOC, or IT department.
Now you: objective 4.2 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
An analyst delays a required notification because several data elements are still unconfirmed. What do the guidelines say to do instead?
Sample question 2 of 3
A responder argues the team cannot notify CISA until root cause is established. Why do the guidelines disagree?
Sample question 3 of 3
A team debates whether a policy violation with no data loss counts as an incident. How does FISMA define one?
Full CySA+ question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.