CS0-003 Reporting and Communication Practice Question
An incident responder is documenting the root cause of a data breach. Which THREE components are essential to include in the root cause analysis section of the incident report? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The technical vulnerability exploited
Root cause analysis should identify the underlying causes, not just the symptoms. It should include the technical failure, the process failure, and the human or organizational factors that contributed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The technical vulnerability exploited
Why this is correct
Documenting the technical vulnerability exploited is central to root cause analysis because it identifies the specific weakness—such as an unpatched CVE, SQL injection, or misconfigured S3 bucket—that allowed the initial compromise. Without this technical detail, the response team cannot prescribe a targeted fix (e.g., patch, configuration change, or WAF rule) to prevent recurrence. The root cause is inseparable from the exact flaw that made the attack viable.
- ✗
The number of records affected
Why it's wrong here
The number of records affected is an impact metric, not a causal factor; it quantifies the confidentiality loss, notification obligations under regulations like GDPR or HIPAA, and potential financial damage. Root cause analysis focuses on why the incident happened, not how much it hurt. Including record count here confuses incident severity assessment with causal investigation, which would misdirect remediation efforts away from the actual source.
- ✗
The name of the employee who clicked the phishing email
Why it's wrong here
Naming the employee who clicked the phishing email is counterproductive and technically imprecise because individual actions are typically a symptom of deeper systemic gaps, not the root cause itself. Human error is expected in any organization; the root cause lies in why the employee was susceptible—lack of phishing-resistant training, missing email filtering, or absent multi-factor authentication. Blaming an individual also deters future reporting and fails to identify the process and technical controls that should have prevented or contained the click.
- ✓
Human factors, such as lack of training
Why this is correct
Human factors, such as insufficient security awareness training, are a legitimate root cause because they directly enable the attack chain—an untrained employee is more likely to click a malicious link or enter credentials into a phishing page. This is a systemic issue, not an individual failing, and it points to a corrective action: implementing role-based, frequent training and phishing simulations. Root cause analysis must include these human-centric contributors because eliminating just the technical vulnerability leaves the human vector open for another exploit variant.
- ✓
Process failures that allowed the vulnerability to exist
Why this is correct
Process failures, such as missing patch management, inadequate change control, or absent vulnerability scanning, are root causes because they allowed the technical vulnerability to persist in the environment. For example, if a critical CVE was known but never applied, the root cause is the broken update process, not merely the vulnerability itself. Correcting the process prevents future vulnerabilities from lingering, which is why process failures are often the true underlying cause behind both technical and human errors.
Go deeper
Related to this question
Learn chapter
SIEM Log Analysis
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
Key term
Root cause analysis
Root cause analysis is a systematic process used to identify the fundamental underlying cause of a problem, rather than just treating its symptoms.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.