During an ongoing ransomware event, the CISO asks for an executive incident status update. The SOC has already isolated affected hosts and is verifying backups. What should the analyst include in the update?
Select an answer to reveal the explanation.
Short Explanation
Think of an executive update like a pilot's quick readout: they're asking whether the fire's contained, what's still burning, and when operations can resume. Raw logs and forensic minutiae don't help leadership decide. You need status, impact, and next steps — not a spreadsheet.
Full Explanation
An executive incident status report exists to support command decisions while an incident is active, so it should translate technical telemetry into operational state. In a ransomware event, leadership needs to know whether containment is holding, which business processes are impaired, what protective actions have been taken, and what recovery milestone is expected next. This lets executives approve isolation, customer notification, regulatory engagement, or recovery sequencing without waiting for forensic certainty. A complete forensic timeline is inappropriate for an active status update because it describes historical events and may not be settled while evidence collection continues. A malware analysis or raw alert dump is too technical for the executive decision layer and can obscure containment status with low-value detail. A future zero-trust roadmap, patch compliance score, or hardening plan is a post-incident improvement topic, not information needed to steer response today. Exam caveat: executive reporting should answer what is happening, what it affects, what is being done, and what decision is needed. Operational check: maintain a status template that lists containment scope, business impact, confirmed actions, open risks, and the next update time.