A SOC confirms EDR shows a ransomware note and unusual outbound HTTPS from a customer database server. The incident commander asks when to notify legal, communications, and system owners. Which communication path is appropriate?
Select an answer to reveal the explanation.
Short Explanation
Think of incident notification like a fire alarm: you don't wait for the fire truck to finish the investigation before telling the building owner. Once you confirm a suspected data compromise, legal, communications, and system owners need to know now. The trap is waiting for perfect certainty; confirmed suspicion is enough to start the communication path.
Full Explanation
Confirmed suspected data compromise is an escalation trigger in incident response playbooks. Legal is notified to assess breach-notification, contractual, and regulatory duties; communications is engaged if disclosure or public messaging risk exists; system owners are notified because they own business impact, maintenance windows, and recovery priorities. This notification is not a final verdict, but a request to begin parallel legal review, message preparation, and operational decisions. Waiting for law enforcement is wrong because law enforcement may investigate crime, but it does not decide internal or regulatory notification duties. Delaying until eradication, recovery, and root cause are complete is wrong because stakeholders need credible incident type and scope early; late notice can miss deadlines and reduce confidence. Waiting until production services are restored is wrong because system owners may need to authorize containment, accept risk, or provide context before eradication and recovery. Exam caveat: CS0-004 tests when to notify roles, not legal advice or regulator names. Operational check: confirm the playbook lists legal, communications, and asset-owner contacts, then test that suspected data compromise triggers the notification workflow.