Courseiva
Reporting and Communication →mediumMultiple Choice

CS0-003 Reporting and Communication Practice Question

During a security incident, the incident response team has identified that a phishing email led to credential theft and lateral movement. Which component of the incident report should detail the sequence of events from initial compromise to containment?

⚠ Common exam trap

CS0-004 often tests the confusion between timeline and root cause analysis; candidates may think root cause analysis includes the sequence of events, but the timeline is the component that details the chronological progression.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Timeline

The timeline component of an incident report details the chronological sequence of events from initial compromise to containment, including the phishing email, credential theft, and lateral movement. This provides a clear narrative for understanding the incident's progression. The timeline is specifically designed to capture the sequence of events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Root cause analysis

    Why it's wrong here

    Root cause analysis (RCA) is a post-incident activity focused on identifying the underlying vulnerability, system misconfiguration, or process failure that allowed the security breach to occur. While critical for preventing future occurrences, RCA does not serve as the chronological log of events, actions, and observations recorded by the incident response team during the active containment phase.

  • ✗

    Impact assessment

    Why it's wrong here

    An impact assessment evaluates the qualitative and quantitative damage caused by an incident, such as data loss, financial exposure, regulatory non-compliance, and operational downtime. This assessment is used to determine the severity of the breach and guide business recovery efforts, rather than documenting the step-by-step chronological progression of the threat actor's activities or the defenders' responses.

  • ✗

    Lessons learned

    Why it's wrong here

    The lessons learned phase occurs during the post-incident activity stage to review the effectiveness of the incident response plan and identify areas for process improvement. It focuses on strategic enhancements to security controls, training, and playbooks rather than establishing the real-time sequence of technical events and forensic milestones observed during the active containment and eradication phases.

  • ✓

    Timeline

    Why this is correct

    A timeline is a critical incident response artifact that chronologically documents the exact sequence of events, including initial vector detection, lateral movement, containment actions, and system restoration. Maintaining an accurate timeline is essential for correlating disparate log sources, establishing a clear chain of custody, and providing a structured narrative for forensic analysis, legal compliance, and stakeholder reporting.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.