Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsHard

During a critical incident, the SOC team determines that the attacker has established a persistent backdoor on several key servers. To prevent the attacker from regaining access, the team decides to rebuild the compromised servers from trusted golden images. Which phase of the incident response lifecycle does this action primarily fall under?

  1. AEradication
  2. BContainment
  3. CPost-Incident Activity
  4. DRecovery
Show answer & explanation

Correct answer: D. Recovery

Rebuilding servers from trusted golden images is part of the Recovery phase. While eradication (removing the backdoor) must happen first, the act of restoring systems to a clean, operational state using known good configurations is the core of recovery.

Why the other options are wrong

  • A. Eradication is removing the root cause and malicious artifacts, which might precede rebuilding but isn't the rebuilding itself.
  • B. Containment is about isolating the threat to prevent spread, not rebuilding systems.
  • C. Post-incident activity is about lessons learned and reporting after the incident has been resolved.

Incident Recovery

The Recovery phase of incident response involves restoring affected systems and services to normal operation, ensuring that they are clean, fully functional, and secure after an incident has been contained and eradicated.

  • Restores normal operations.
  • Often involves rebuilding from backups or images.
  • Follows eradication and precedes lessons learned.

Memory trick: I C E R R L: I See Every Risky, Response-Driven Loop.

More Security Operations questions