After a phishing incident, leadership asks for the post-incident report. The analyst has a detailed timeline of alerts, containment actions, and recovery steps. To show why the incident occurred and how to prevent recurrence, what should the report emphasize?
Select an answer to reveal the explanation.
Short Explanation
Think of a post-incident report like a car crash investigation: the timeline tells you the car moved, but the report must tell you why it hit. You need root cause and preventive changes, not just a neat sequence of alerts. The trap is polishing the story while leaving the hazard in place.
Full Explanation
A post-incident report exists to turn a response into organizational learning. The core mechanism is root-cause analysis: identify the condition, process gap, or control failure that allowed the phishing incident to succeed, then recommend preventive changes such as policy, training, segmentation, or automation adjustments. A timeline is evidence, not explanation. A chronological timeline of all alerts and response actions is useful for reconstruction and auditability, but it only records what occurred and cannot by itself demonstrate why the event happened or how recurrence will be reduced. A complete list of affected systems, indicators, and recovery timestamps supports asset recovery, impact assessment, and follow-up containment, yet it remains an inventory of consequences rather than a causal account. An executive summary of containment decisions and communication steps helps leadership understand the response posture, but it focuses on management actions taken during the incident instead of the underlying weakness that enabled the incident. Exam caveat: CompTIA expects post-incident communication to support improvement, so choose the answer that names cause and prevention, not evidence or status. Operational check: before publishing the report, verify that each major finding links an observed indicator to a root cause and a specific remediation owner.