During an active cybersecurity incident, responders must assume that systems associated with the compromise may no longer provide trustworthy confidentiality or integrity until their status has been established. If the incident could involve the organization's email infrastructure, discussing response strategy, investigative findings, affected assets, or containment actions through corporate email could unintentionally provide the attacker with intelligence about the organization's response.
Therefore, the email system may be compromised is the strongest explanation. Incident-response communication plans should define approved communication methods, relevant stakeholders, escalation paths, and alternative communication channels so responders can continue coordinating when ordinary enterprise systems are unavailable or untrusted. NIST's current incident-response guidance emphasizes integrating communication and stakeholder coordination throughout response activities.
Option C is too broad. Modern email commonly uses transport encryption, although encryption alone would not make a compromised mailbox or server trustworthy. Option D concerns public-relations coordination but does not explain why email itself should be avoided. Option A describes a specific gateway vulnerability that the scenario does not establish.
The core principle is out-of-band communication : when normal communication infrastructure may be under attacker control, responders should use a previously approved independent channel.
Study Guide Reference: Reporting and Communication → Incident Communications → Communication Plan → Out-of-Band Communications → Stakeholder Coordination → Compromised Communication Channels.