Courseiva
mediumMultiple Select

CS0-003 Practice Question: During the post-incident analysis phase of an…

During the post-incident analysis phase of an incident response process, which of the following activities are considered essential best practices? Choose all that apply. (There are four correct answers.)

⚠ Common exam trap

CompTIA often tests the distinction between 'immediate containment actions' and 'post-incident analysis best practices,' where candidates mistakenly select actions that are appropriate during the containment phase (like preserving evidence) but not during the analysis phase, or they confuse notification requirements with internal investigation priorities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Creating a detailed timeline of the incident from detection to containment and recovery.

A detailed timeline is essential for reconstructing the sequence of events, identifying the initial compromise vector, and measuring response effectiveness. It provides a factual basis for all subsequent analysis and reporting, ensuring that the incident response team can accurately assess the scope and impact of the incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Creating a detailed timeline of the incident from detection to containment and recovery.

    Why this is correct

    Building a comprehensive timeline that stitches together detection, containment, and recovery timestamps from every relevant log source, including SIEM, firewall, and EDR data, is essential to post-incident analysis because it lets the team see exactly how much time elapsed at each stage and expose delays that root cause analysis and playbook updates will later address.

  • ✓

    Identifying gaps in existing security controls that allowed the incident to occur.

    Why this is correct

    Identifying which security controls failed or were missing, such as an unpatched CVE, an overly permissive firewall rule, or absent multifactor authentication, is a core post-incident deliverable because it converts the incident into actionable remediation items, ensuring the same class of failure does not allow a repeat compromise.

  • ✓

    Updating playbooks and incident response plans based on lessons learned.

    Why this is correct

    Feeding lessons learned back into the incident response plan and runbooks closes the loop on the entire IR lifecycle, turning a one-time investigation into measurable improvement in future mean time to respond; without this step, the same procedural mistakes tend to recur in the next incident.

  • ✓

    Performing a root cause analysis to determine the underlying cause of the incident.

    Why this is correct

    Root cause analysis, often performed with techniques like the 5 Whys or fault tree analysis, traces the incident back past its immediate symptoms to the fundamental technical or process failure that allowed it to occur, which is necessary before any control gap or playbook update can be meaningfully targeted.

  • ✗

    Immediately deleting all logs related to the incident to free up storage space.

    Why it's wrong here

    Deleting incident-related logs during post-incident analysis destroys the evidentiary and forensic record needed for root cause analysis, timeline reconstruction, and any subsequent legal or regulatory proceeding; this action also likely violates data retention and chain-of-custody requirements and is never appropriate regardless of storage pressure.

  • ✗

    Notifying law enforcement and regulatory bodies before conducting any internal investigation.

    Why it's wrong here

    Notifying law enforcement or regulators before conducting any internal investigation risks reporting inaccurate or incomplete information, since the organization has not yet confirmed scope, root cause, or affected data; proper practice is to perform enough internal triage to understand the incident before external notifications, which are governed by specific legal timelines rather than sheer immediacy.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.