Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsEasy

A security auditor is reviewing an organization's incident response plan. The plan includes a step to gather all relevant information about a detected security incident, including logs, network traffic, and affected systems. Which phase of the incident response process does this step primarily belong to?

  1. AIdentification
  2. BContainment
  3. CRecovery
  4. DEradication
Show answer & explanation

Correct answer: A. Identification

Gathering information about a detected security incident, such as logs and network traffic, is a crucial part of the Identification phase of incident response, aiming to understand the scope and nature of the incident.

Why the other options are wrong

  • B. Containment focuses on limiting the damage of the incident.
  • C. Recovery involves restoring systems to normal operation.
  • D. Eradication involves removing the cause of the incident.

Incident Identification

The initial phase of incident response focused on detecting security events, determining if they are incidents, and gathering critical information about their nature and scope.

  • First phase of incident response.
  • Involves monitoring, analysis, and validation.
  • Aims to understand 'what happened'.

Memory trick: I Can't Eat Raw Carrots, Post-incident.

More Cybersecurity Fundamentals questions