Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsEasy

A Security Operations Center (SOC) analyst is reviewing logs and notices an unusual increase in network traffic originating from an internal server to an external IP address known for hosting command-and-control (C2) infrastructure. All other network activity from this server appears normal. Which phase of the incident response lifecycle is the analyst primarily engaged in?

  1. AIdentification
  2. BRecovery
  3. CEradication
  4. DContainment
Show answer & explanation

Correct answer: A. Identification

The analyst is observing an anomaly and recognizing it as a potential security incident, which is the core activity of the identification phase. They are not yet removing the threat, restoring systems, or stopping the spread.

Why the other options are wrong

  • B. Recovery focuses on restoring affected systems and services to normal operation.
  • C. Eradication involves removing the threat from the environment.
  • D. Containment aims to stop the spread of the incident and limit its impact.

Incident Identification

The first phase of incident response, involving the detection of security events and their validation as actual incidents requiring action.

  • Involves monitoring security tools and logs.
  • Aims to detect anomalies and suspicious activities.
  • Determines if a security event constitutes an incident.

Memory trick: I Can Read Every Report

More Security Operations questions