Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsHard

A SOC team is reviewing the effectiveness of their security controls against a recent phishing campaign that successfully compromised several user accounts. They are now updating their security awareness training and email filtering rules based on the lessons learned from this incident. In which phase of the incident response lifecycle would these actions typically occur?

  1. ARecovery
  2. BIdentification
  3. CPost-Incident Activity
  4. DEradication
Show answer & explanation

Correct answer: C. Post-Incident Activity

Updating security awareness training and email filtering rules based on lessons learned from an incident are activities that aim to improve future security posture and prevent recurrence. These actions are characteristic of the Post-Incident Activity (or Lessons Learned) phase of the incident response lifecycle, which occurs after the incident has been fully resolved.

Why the other options are wrong

  • A. Recovery is restoring systems, not updating training or rules.
  • B. Identification is about detecting the incident, not learning from it afterward.
  • D. Eradication is removing the threat, not improving long-term defenses.

Post-Incident Activity

Post-Incident Activity, also known as 'Lessons Learned,' is the final phase of incident response where the organization reviews the incident, identifies what worked and what didn't, and implements improvements to processes, technologies, and training to enhance future security.

  • Occurs after incident resolution.
  • Aims to improve future readiness.
  • Includes documentation, policy updates, and training.

Memory trick: I C E R R L: I See Every Risky, Response-Driven Loop.

More Security Operations questions