CS0-003 Reporting and Communication Practice Question
After a security incident, which component of the incident report provides a chronological sequence of events from detection to recovery?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Timeline
The timeline is a critical component that shows the order of events during an incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Timeline
Why this is correct
The timeline is the chronological reconstruction of every observable event leading up to, during, and after the security incident. It consolidates artifacts like log entries, file system changes, network flows, and user actions into a coherent sequence. This component is foundational because it enables analysts to map the attack lifecycle and determine the exact order of compromise, which is essential for effective containment and eradication.
- ✗
Lessons learned
Why it's wrong here
Lessons learned is a post-incident activity that reviews the effectiveness of the response and identifies process improvements, such as policy changes or additional training. It relies on the timeline and other documentation but does not itself document the sequence of events. This phase occurs after the incident is fully resolved, making it a retrospective component rather than a during-incident artifact.
- ✗
Root cause
Why it's wrong here
Root cause analysis is a deep-dive investigation that pinpoints the underlying vulnerability, misconfiguration, or flaw that allowed the incident to occur. It answers 'why' the attack succeeded, whereas the timeline answers 'what happened and in what order.' Although root cause is a critical finding, it is a derived conclusion from the timeline, not the component that records the sequence of events.
- ✗
Impact assessment
Why it's wrong here
Impact assessment quantifies the consequences of the incident, including data exfiltration volumes, financial losses, system downtime, and regulatory exposure. It measures the severity and scope of damage, often using the timeline to correlate specific actions with their outcomes. However, it does not document the chronological sequence itself; it is a separate evaluation of the blast radius rather than a record of event order.
Go deeper
Related to this question
Learn chapter
Endpoint Detection and Response
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.