Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsMedium

A SOC analyst is investigating a suspected malware infection on a user's workstation. The initial alert came from an Endpoint Detection and Response (EDR) solution. The analyst has already contained the system by isolating it from the network. What is the MOST critical next step to ensure the immediate removal of the threat and prevent re-infection?

  1. AExecute an anti-malware scan and remove identified threats.
  2. BBegin collecting volatile data for forensic analysis.
  3. CPerform a full system backup of the compromised workstation.
  4. DUpdate the user's security awareness training.
Show answer & explanation

Correct answer: A. Execute an anti-malware scan and remove identified threats.

After containment, the next critical step in incident response is eradication. Running an anti-malware scan and removing identified threats directly addresses the eradication of the malware from the compromised system, preventing its continued operation and potential re-infection.

Why the other options are wrong

  • B. Collecting volatile data is part of analysis/identification, which often precedes or happens in parallel with containment, but eradication is the immediate next step for threat removal.
  • C. Backing up a compromised system before eradication risks backing up the malware itself, which is not ideal for recovery.
  • D. Updating security awareness is a post-incident activity, not an immediate technical step for threat removal.

Incident Eradication

The phase of incident response focused on removing the root cause of the incident and all traces of the attacker's presence from affected systems.

  • Follows containment and often analysis.
  • Involves cleaning compromised systems.
  • Aims to prevent re-infection.

Memory trick: After you contain, you eradicate!

More Security Operations questions