CS0-003 Reporting and Communication Practice Question
A cybersecurity analyst is preparing an incident report after a data breach. Which TWO components are essential to include? (Select TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Root cause
Root cause and timeline are standard components of incident reports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Root cause
Why this is correct
Root cause analysis identifies the fundamental underlying reason for the security incident, such as an unpatched vulnerability, misconfigured firewall rule, or successful phishing campaign. For an incident report, establishing the root cause is critical because it guides remediation efforts and prevents recurrence, and it satisfies regulatory and stakeholder requirements for understanding why the incident occurred. Without a root cause, the report is merely descriptive, not prescriptive.
- ✓
Timeline
Why this is correct
A timeline documents the chronological sequence of events from initial compromise through detection, containment, eradication, and recovery. It provides a frame of reference for correlating log entries, user actions, and system changes, which is essential for incident responders to identify attack vectors and determine impact. While a timeline is a core component of a comprehensive incident report, it serves as supporting evidence rather than the primary conclusion of the analysis.
- ✗
Budget forecast
Why it's wrong here
A budget forecast projects future financial expenditures and revenue, which is unrelated to the operational and technical details needed in an incident report. While cost data may appear in a post-incident review for business continuity or insurance claims, a forward-looking budget forecast does not explain what happened, how it happened, or what actions were taken. Including it would clutter the report with non-technical, financial planning information that is outside the scope of incident documentation.
- ✗
Employee performance review
Why it's wrong here
An employee performance review evaluates an individual's job performance, skills, and productivity, which is not a component of an incident report. Even when human error contributed to the incident, the report should focus on the action and its technical consequence, not on personal performance assessments. Adding performance reviews would introduce HR-sensitive information and shift the focus from system remediation to personnel evaluation, which is inappropriate and potentially legally problematic.
- ✗
Marketing analysis
Why it's wrong here
A marketing analysis examines market trends, customer demographics, and promotional strategies, which has no relevance to a cybersecurity incident report. Incident reports are technical, operational documents intended for IT, management, and oversight bodies; they describe technical details like indicators of compromise, exploited vulnerabilities, and mitigation steps. Inserting marketing analysis would be extraneous and dilute the report's purpose of accurate, actionable information for security improvement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.