CS0-003 Reporting and Communication Practice Question
A cybersecurity analyst is preparing an incident report after a data breach. Which TWO components are essential to include? (Select TWO.)
⚠ Common exam trap
CS0-004 often tests whether candidates can distinguish incident-report essentials (root cause, timeline, impact, IoCs) from unrelated business artifacts like budgets or HR reviews.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Root cause
Option A (Root cause) is correct because an incident report must document the underlying vulnerability or failure that enabled the breach, such as an unpatched CVE, misconfigured firewall rule, or successful phishing vector, so remediation can prevent recurrence. Option B (Timeline) is correct because a chronological sequence of events—initial compromise, detection, containment, and eradication timestamps—establishes scope, supports forensic reconstruction, and satisfies regulatory/audit requirements. The unmarked options do not belong: budget forecast (C) is a financial planning artifact, employee performance review (D) is an HR matter, and marketing analysis (E) is unrelated to security incident documentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Root cause
Why this is correct
Root cause analysis identifies the fundamental underlying reason for the security incident, such as an unpatched vulnerability, misconfigured firewall rule, or successful phishing campaign. For an incident report, establishing the root cause is critical because it guides remediation efforts and prevents recurrence, and it satisfies regulatory and stakeholder requirements for understanding why the incident occurred. Without a root cause, the report is merely descriptive, not prescriptive.
- ✓
Timeline
Why this is correct
A timeline documents the chronological sequence of events from initial compromise through detection, containment, eradication, and recovery. It provides a frame of reference for correlating log entries, user actions, and system changes, which is essential for incident responders to identify attack vectors and determine impact. While a timeline is a core component of a comprehensive incident report, it serves as supporting evidence rather than the primary conclusion of the analysis.
- ✗
Budget forecast
Why it's wrong here
A budget forecast projects future financial expenditures and revenue, which is unrelated to the operational and technical details needed in an incident report. While cost data may appear in a post-incident review for business continuity or insurance claims, a forward-looking budget forecast does not explain what happened, how it happened, or what actions were taken. Including it would clutter the report with non-technical, financial planning information that is outside the scope of incident documentation.
- ✗
Employee performance review
Why it's wrong here
An employee performance review evaluates an individual's job performance, skills, and productivity, which is not a component of an incident report. Even when human error contributed to the incident, the report should focus on the action and its technical consequence, not on personal performance assessments. Adding performance reviews would introduce HR-sensitive information and shift the focus from system remediation to personnel evaluation, which is inappropriate and potentially legally problematic.
- ✗
Marketing analysis
Why it's wrong here
A marketing analysis examines market trends, customer demographics, and promotional strategies, which has no relevance to a cybersecurity incident report. Incident reports are technical, operational documents intended for IT, management, and oversight bodies; they describe technical details like indicators of compromise, exploited vulnerabilities, and mitigation steps. Inserting marketing analysis would be extraneous and dilute the report's purpose of accurate, actionable information for security improvement.
Go deeper
Related to this question
Learn chapter
Digital Forensic Evidence Collection
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.