Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsHard

A security analyst observes numerous log entries in the SIEM indicating repeated attempts to access a highly sensitive database from an internal IP address that is not authorized for such access. The attempts are using valid credentials for a service account. Further investigation reveals that the service account credentials were recently compromised in a phishing attack. The analyst needs to determine the appropriate immediate action. Which of the following best describes the MOST effective immediate containment strategy?

  1. AIsolate the source internal IP address from the network.
  2. BDisable the compromised service account immediately.
  3. CBlock the database access attempts at the database firewall.
  4. DNotify the service account owner and reset the password.
Show answer & explanation

Correct answer: B. Disable the compromised service account immediately.

The core issue here is the compromised valid credentials. While isolating the IP or blocking at the firewall might temporarily stop the current access attempts, the compromised credentials still exist and could be used from another source. Disabling the compromised service account immediately neutralizes the threat at its source by rendering the stolen credentials useless, providing the most effective and immediate containment.

Why the other options are wrong

  • A. Isolating the IP is a good step but doesn't address the root cause (compromised credentials) and the attacker might move to another system.
  • C. Blocking at the database firewall is a good temporary measure but the compromised credentials could still be used to attack other resources from potentially different sources.
  • D. Notifying and resetting is part of the process, but disabling is the immediate action to stop the active threat while the password reset is being coordinated.

Containment (Credentials)

Immediate actions to prevent further unauthorized use of compromised user or service account credentials.

  • Prioritize disabling or revoking access for compromised accounts.
  • Prevents attackers from using stolen credentials elsewhere.
  • Often combined with network isolation or blocking for comprehensive containment.

Memory trick: When the key is stolen, first change the lock, then secure the door.

More Security Operations questions