CS0-003 Reporting and Communication Practice Question
During a security incident, the incident response team has identified that a phishing email led to credential theft and lateral movement. Which component of the incident report should detail the sequence of events from initial compromise to containment?
⚠ Common exam trap
CS0-004 often tests the confusion between timeline and root cause analysis; candidates may think root cause analysis includes the sequence of events, but the timeline is the component that details the chronological progression.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Timeline
The timeline component of an incident report details the chronological sequence of events from initial compromise to containment, including the phishing email, credential theft, and lateral movement. This provides a clear narrative for understanding the incident's progression. The timeline is specifically designed to capture the sequence of events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Root cause analysis
Why it's wrong here
Root cause analysis (RCA) is a post-incident activity focused on identifying the underlying vulnerability, system misconfiguration, or process failure that allowed the security breach to occur. While critical for preventing future occurrences, RCA does not serve as the chronological log of events, actions, and observations recorded by the incident response team during the active containment phase.
- ✗
Impact assessment
Why it's wrong here
An impact assessment evaluates the qualitative and quantitative damage caused by an incident, such as data loss, financial exposure, regulatory non-compliance, and operational downtime. This assessment is used to determine the severity of the breach and guide business recovery efforts, rather than documenting the step-by-step chronological progression of the threat actor's activities or the defenders' responses.
- ✗
Lessons learned
Why it's wrong here
The lessons learned phase occurs during the post-incident activity stage to review the effectiveness of the incident response plan and identify areas for process improvement. It focuses on strategic enhancements to security controls, training, and playbooks rather than establishing the real-time sequence of technical events and forensic milestones observed during the active containment and eradication phases.
- ✓
Timeline
Why this is correct
A timeline is a critical incident response artifact that chronologically documents the exact sequence of events, including initial vector detection, lateral movement, containment actions, and system restoration. Maintaining an accurate timeline is essential for correlating disparate log sources, establishing a clear chain of custody, and providing a structured narrative for forensic analysis, legal compliance, and stakeholder reporting.
Go deeper
Related to this question
Learn chapter
Security Metrics and KPIs
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.