An enterprise SOC confirms a ransomware incident affecting an HR file share. The analyst prepares a public statement listing affected applications, suspected IOCs, and recovery status. Communications and legal ask the analyst to coordinate public disclosure. What should the analyst do first?
Select an answer to reveal the explanation.
Short Explanation
Think of public messaging like publishing a lab report: you don't release raw data before peer review. You get legal and comms to validate what's confirmed, what's sensitive, and what can be said. The trap is treating a good technical summary as ready for the public.
Full Explanation
In CS0-004 reporting, public disclosure is not a technical handoff; it is a controlled communication process. The analyst's role is to supply accurate, validated findings so incident management, legal, and communications can decide wording, timing, and scope. This matters because technical artifacts can contain unconfirmed indicators, customer data, forensic details, or privileged information. Review also aligns the message with breach-notification duties and avoids statements that could harm investigation or create liability. The option urging immediate publication fails because speed without review risks releasing inaccurate or sensitive details. The option advocating full transparency with every indicator fails because transparency is not a license to disclose unvalidated or operationally risky information. The option requiring full restoration before any external statement fails because coordinated incident communications may need to occur while containment or recovery continues. Exam caveat: choose the answer that emphasizes cross-functional review and accuracy over raw technical completeness or unilateral release. Operational check: have the incident commander, legal, and communications approve a fact-checked statement and record the approval in the incident ticket.