An SOC analyst is drafting the communication plan for a confirmed ransomware event affecting customer data. Which action best reflects the need for incident communication beyond the technical response team?
Select an answer to reveal the explanation.
Short Explanation
Think of an incident like a house fire: you don't just tell the firefighters. You also need the family, the lawyer, and the neighborhood ready with the right story. You keep the technical details in the SOC and route approved updates through legal, PR, and executives.
Full Explanation
An incident communication plan must coordinate information flow across functions that own legal exposure, public reputation, and business decision-making. Technical teams need detailed indicators and containment status, while legal, public relations, and executive stakeholders need accurate, approved, non-technical updates so they can manage regulatory obligations, customer notifications, media response, and resource decisions without leaking sensitive evidence. Publishing full forensic details on a public page is wrong because it can expose customer data, compromise investigation integrity, and create legal liability before counsel reviews the facts. Restricting all updates to SOC and IT operations is wrong because executives must authorize business actions, legal must assess notification duties, and public relations must prepare external messaging in parallel with containment. Asking a vulnerability scanner to produce a CVSS v4 report for a customer portal is wrong because CVSS measures vulnerability severity, not incident status, and does not replace coordinated stakeholder messaging. Exam caveat: CompTIA expects analysts to distinguish technical reporting from incident communication governance. Operational check: Confirm the plan includes an approved stakeholder list, message owner, update cadence, and legal review gate before external or executive distribution.