mediumMultiple SelectObjective-mapped
CS0-003 Practice Question: A cybersecurity analyst is preparing a…
A cybersecurity analyst is preparing a post-incident report for a data breach that affected multiple business units. Which three of the following elements should be included in the report to ensure effective communication and support future prevention? (Choose three.)
⚠ Common exam trap
CompTIA often tests the distinction between operational data (e.g., raw packet captures, credentials) and actionable intelligence (e.g., timeline, root cause, recommendations) to see if candidates understand that a post-incident report is a high-level communication tool, not a data dump.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A detailed timeline of the incident, including detection and response actions
A detailed timeline of the incident, including detection and response actions, is correct because it provides a chronological record essential for understanding the sequence of events, assessing response effectiveness, and meeting regulatory reporting requirements. Root cause analysis and contributing factors are correct because they identify the underlying technical or procedural failures (e.g., unpatched vulnerability, misconfigured firewall rule) that must be addressed to prevent recurrence. Recommendations for remediation and process improvements are correct because they translate findings into actionable steps, such as implementing multi-factor authentication or updating incident response playbooks, which directly support future prevention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A detailed timeline of the incident, including detection and response actions
Why this is correct
A detailed timeline of the incident, including detection and response actions, is essential for reconstructing the sequence of events and evaluating the effectiveness of the security team's response. It enables stakeholders to identify gaps in visibility, slow detection, or delayed containment, and it provides a factual basis for any regulatory or legal reporting requirements. Without a timeline, the report lacks the chronological context needed to measure response times and to validate that appropriate actions were taken in a timely manner.
- ✗
The specific usernames and passwords of affected accounts
Why it's wrong here
Including specific usernames and passwords of affected accounts is a serious security risk and violates principles of data minimization. Post-incident reports are often shared broadly with management, legal, and external parties; exposing credentials could lead to further compromise if the report is mishandled or disclosed. The report should reference only the account types and the required remediation (e.g., forced rotation) without revealing actual secrets, keeping the document safe for wider distribution.
- ✓
Root cause analysis and contributing factors
Why this is correct
Root cause analysis and contributing factors identify the fundamental weaknesses—such as an unpatched vulnerability, a misconfigured firewall, or a phishing failure—that allowed the breach to occur. This analysis is critical because it moves beyond superficial symptoms to address the systemic issues that, if left unresolved, could be exploited again. It also helps prioritize security investments by showing which controls were ineffective and what conditions allowed the attack to succeed.
- ✓
Recommendations for remediation and process improvements
Why this is correct
Recommendations for remediation and process improvements provide clear, actionable guidance for closing the gaps exposed by the incident, such as deploying patches, segmenting networks, or enhancing threat hunting capabilities. These recommendations should be prioritized by risk and feasibility, and they often include a roadmap with owners and deadlines to ensure accountability. This section transforms the report from a historical record into a forward-looking tool that drives continuous improvement in the organization's security posture.
- ✗
The raw packet capture data from the breach period
Why it's wrong here
Raw packet capture data from the breach period is inherently too large and low-level to be useful in a post-incident report intended for management, legal, or other non-technical stakeholders. It also may contain sensitive information that is not directly relevant to the incident, and interpreting it requires specialized tools and expertise. The report should instead include extracted, analyzed artifacts—such as connection logs, NetFlow summaries, or key transaction details—that present the same evidence in a digested and actionable form.
- ✗
A list of all employees’ personal contact information for notification
Why it's wrong here
A list of all employees' personal contact information for notification is extraneous to the technical findings of a data breach and raises significant privacy and confidentiality concerns. Notification procedures typically follow a separate, legally approved process led by HR or privacy officers, not the cybersecurity incident report itself. Including such sensitive personal data in a document that may be circulated beyond intended recipients increases the risk of secondary data exposure and violates data protection principles.
Go deeper
Related to this question
Learn chapter
SIEM Log Analysis
Key term
Firewall rule
A firewall rule is a set of conditions that tells a firewall which network traffic to allow or block based on attributes like source, destination, port, and protocol.
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.