CS0-003 Reporting and Communication Practice Question
Which component of an incident report describes the sequence of events from detection to resolution?
⚠ Common exam trap
CS0-004 often tests the distinction between the 'what/when' (timeline) and the 'why' (root cause) or 'so what' (impact assessment, lessons learned) sections of an incident report, causing candidates to confuse documentation of events with analysis of causes or outcomes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Timeline
The timeline (also called the chronology or sequence of events) is the section of an incident report that documents the chronological order of activities from initial detection through containment, eradication, recovery, and closure. It provides a factual, time-stamped record that allows responders and reviewers to reconstruct exactly what happened and when. This is distinct from root cause analysis, which explains why the incident occurred, and from impact assessment, which quantifies the damage or business effect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Root cause
Why it's wrong here
Root cause analysis identifies the underlying technical or process failure that allowed the incident to occur, such as an unpatched vulnerability or a misconfigured control, which explains why the incident happened rather than the chronological order in which events unfolded.
- ✗
Impact assessment
Why it's wrong here
Impact assessment quantifies the scope of damage, such as affected systems, data exposed, downtime, and financial cost, giving a snapshot of consequences rather than a chronological account of when detection, containment, and eradication activities actually took place.
- ✗
Lessons learned
Why it's wrong here
Lessons learned is a forward-looking section captured during the post-incident review that documents process improvements and control gaps to prevent recurrence, making it a reflective summary produced after the fact rather than a record of the incident's chronological progression.
- ✓
Timeline
Why this is correct
Correct. The timeline is the section of an incident report that chronologically documents every key event, from initial detection through containment, eradication, and recovery, typically with precise timestamps, giving responders and auditors a clear record of how the incident unfolded and how quickly the team reacted.
Go deeper
Related to this question
Learn chapter
GDPR and HIPAA Incident Reporting
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.