Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsEasy
A Security Operations Center (SOC) analyst is reviewing network flow data and observes a sudden, significant increase in outbound traffic to an unusual foreign IP address from an internal server that typically has low external communication. Further investigation reveals that this server hosts sensitive customer data. Which stage of the incident response process is the analyst currently operating within?
- AIdentification
- BPost-Incident Analysis
- CEradication
- DRecovery
Show answer & explanationAnswer & explanation
Correct answer: A. Identification
The analyst is observing anomalies and collecting initial information to determine if an incident has occurred, which aligns with the Identification stage of incident response. This stage focuses on detecting and assessing potential security incidents.
Why the other options are wrong
- B. Post-Incident Analysis (or Lessons Learned) occurs after an incident is fully resolved, focusing on improving future response.
- C. Eradication involves removing the cause of the incident and restoring affected systems, which comes after identification and containment.
- D. Recovery involves restoring systems and services to normal operation after an incident has been contained and eradicated.
Incident Identification
The first stage of the incident response process, focused on detecting and analyzing potential security events to determine if an actual security incident has occurred.
- Involves monitoring logs, alerts, and network traffic.
- Aims to confirm or deny a security event as an incident.
- Often relies on SIEM systems and analyst expertise.
Memory trick: I C E R R L - Investigate, Contain, Eradicate, Recover, Report, Learn.