Practise vocabulary and phrases for reconstructing incident timelines: temporal language, signal detection, alert vocabulary, and chronological narration.
0 / 10 completed
1 / 10
In a postmortem timeline, 'T+0' refers to ___.
T+0 (time zero) marks the reference point — usually the triggering event (first alert firing, deployment completing, or first user report). All subsequent timeline entries are relative to this point (T+5m, T+1h, etc.).
2 / 10
'Prior to the incident, the system exhibited ___ signs of degradation' — which word correctly fills the blank?
Precursor signs (leading indicators, early warnings) are signals that appeared before the full incident — elevated error rates, slow queries, increased latency. Identifying them helps improve detection in future.
3 / 10
'___ bias' is the tendency to evaluate past decisions with knowledge of the outcome — something to explicitly guard against in postmortems.
Hindsight bias makes past decisions look obviously wrong when viewed with knowledge of what happened. Postmortem facilitators must explicitly acknowledge what responders knew at each moment in the timeline, not what we know now.
4 / 10
'The on-call engineer was ___ of the issue at 14:32 UTC, when the alert fired' — which word fits?
'Notified' is the neutral, factual language for when someone received an alert. Blameless timelines use neutral notification language ('was notified', 'became aware', 'observed') rather than accountability language ('failed to', 'should have').
5 / 10
'Time to ___ (TTD)' measures how long it took from the incident's start until it was first detected by monitoring or users.
Time to Detect (TTD) is the interval from incident onset to first detection alert. Reducing TTD is a key reliability improvement goal — achieved through better monitoring coverage, lower alert thresholds, and synthetic traffic checks.
6 / 10
Alex, the SRE, is drafting a timeline reconstruction for the recent database outage. He needs to accurately describe the sequence of events. Which phrasing best captures the immediate aftermath when the primary database server went down?
Option A: 'The system experienced an instantaneous failure due to unforeseen hardware malfunction.'
Option B: 'There was a sudden, unrecoverable service interruption at 10:35 UTC, followed by immediate investigation and escalation.'
Option C: 'A minor performance degradation occurred at 10:34 UTC, leading to eventual system instability.'
Option D: 'The application began reporting errors approximately 2 minutes after the initial server crash.'
This scenario focuses on precise communication during a critical incident. Option B correctly frames the immediate response – highlighting the time of failure and subsequent actions. Options A and C are too vague; 'instantaneous failure' isn't always accurate, and 'minor performance degradation' minimizes the severity. Option D describes a delayed consequence, not the initial event.
7 / 10
Sarah, a developer reviewing a PR for a new microservice, notices the commit message states: 'Fixed bug.'. What's the most appropriate response to encourage more detailed documentation in timeline reconstruction?
Option A: 'Great job on fixing the bug!'
Option B: 'Could you please add a brief description of the root cause and any immediate impact this fix had?'
Option C: 'This is perfectly acceptable; we don't need excessive detail in every commit.'
Option D: 'Just ensure the code passes all tests.'
Effective PR reviews contribute significantly to accurate timeline reconstruction. Option B prompts for crucial context – the root cause and impact – which are vital components of a timeline. Options A is purely positive and doesn't address documentation needs; C accepts insufficient detail, and D focuses solely on code functionality.
8 / 10
Ben, during a standup meeting, describes the recent deployment. He says: 'We rolled out version 2.1. The servers are working.'. Considering timeline reconstruction principles, what's the missing information that would be most valuable?
Option A: 'The deployment was successful and didn't require any rollback.'
Option B: 'We deployed version 2.1 to production at 16:00 UTC, and initial monitoring shows no immediate issues.'
Option C: 'The team worked hard on the deployment.'
Option D: 'We followed our standard deployment process.'
Standup updates should provide concrete details relevant to incident analysis. Option B directly addresses key timeline markers – the deployment time and initial observations. While options A, C, and D are generally good practices, they don't contribute to reconstructing the sequence of events surrounding an incident.
9 / 10
Chloe is drafting a Slack message to notify the on-call engineer about a monitoring alert. The alert details include: 'High CPU utilization detected on Web Server 1'. What information should she *avoid* including in this initial notification, considering timeline reconstruction?
Option A: 'The alert was triggered at 08:45 UTC.'
Option B: 'The alert is currently impacting user response times.'
Option C: 'We're investigating the cause of the high CPU utilization.'
Option D: 'This is a critical alert – please investigate immediately.'
While urgency is important in Slack notifications, including subjective impacts (like 'impacting user response times') can be misleading without further context. This introduces potential bias and doesn't provide the precise data needed for timeline reconstruction. Option A provides a timestamp, but it's less informative than the impact. Options C and D are commands that don't add to the factual record.
10 / 10
David is analyzing an API response from a monitoring system related to a recent outage. The response shows: 'Request latency increased by 3x'. What does this primarily indicate in the context of timeline reconstruction?
Option A: 'The server had a full CPU load.'
Option B: 'There was a significant delay in processing requests, likely contributing to the outage.'
Option C: 'The API endpoint is experiencing high traffic volume.'
Option D: 'The database connection pool is exhausted.'
While the other options could be related causes, 'Request latency increased by 3x' directly points to a performance issue – a delay in request processing. This is a key indicator of a timeline event and its impact on system behavior, which is what reconstruction focuses on. It's a measurable observation that helps pinpoint the sequence leading to the outage.
What will I practice in "Timeline Reconstruction Language"?
This is a Post Incident Facilitation exercise set. It walks through 10 scenario-based multiple-choice questions built around real usage of post incident facilitation terminology that IT professionals encounter on the job.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to complete with no account, sign-up, or paywall.
How many questions are in this exercise?
This set contains 10 questions. Each one shows immediate feedback and a detailed explanation after you answer, so you learn the correct usage right away rather than waiting for a final score.
Do I need prior experience to complete this exercise?
No prior experience is required. Each question includes a full explanation covering the reasoning behind the correct answer, so the exercise itself teaches the post incident facilitation vocabulary as you go.
Can I retry the exercise if I get questions wrong?
Yes — use the "Try again" button on the results screen to reset your answers and go through all the questions again. There is no limit on attempts.
Is my progress saved?
Your answers and score for the current session are tracked in the browser as you go. No account or login is needed, and there is nothing to install.
What if I don't understand a term used in a question?
Read the explanation shown after you answer each question — it breaks down the correct term in plain English with a real-world example. You can also check the site Glossary for quick definitions.
How is this different from reading a blog article on the topic?
Exercises like this one are interactive drills that test and reinforce specific vocabulary through multiple-choice questions, while blog articles explain concepts in prose. Practising here after reading builds active recall, not just passive recognition.
Where can I find more Post Incident Facilitation exercises?
See the Post Incident Facilitation exercises hub for the full set of related pages, or browse all exercise categories from the main Exercises index.
Can I use this exercise to prepare for a technical interview?
Yes — post incident facilitation vocabulary comes up often in technical discussions and interviews. Pair this exercise with our dedicated Interview Preparation section for role-specific practice.