Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsMedium

A SOC analyst is investigating an alert from the SIEM about a potential data exfiltration from a critical database server. The alert indicates a large volume of outbound traffic to an external IP address not on the whitelist. Before taking any containment actions, the analyst wants to confirm the nature of the traffic. Which of the following is the MOST appropriate next step in the incident response process?

  1. AIsolate the database server from the network to prevent further exfiltration.
  2. BReview network flow logs and packet captures for the suspicious traffic to confirm content.
  3. CNotify legal counsel and public relations team about a potential data breach.
  4. DImmediately block the suspicious outbound IP address at the firewall.
Show answer & explanation

Correct answer: B. Review network flow logs and packet captures for the suspicious traffic to confirm content.

Before taking drastic containment actions like blocking or isolating, it's crucial to confirm the nature of the traffic to avoid false positives and unnecessary disruption. Reviewing network logs and packet captures allows the analyst to verify if the traffic is indeed malicious data exfiltration.

Why the other options are wrong

  • A. Isolating the server is a containment action, also premature without confirming the incident.
  • C. Notifying external parties is part of post-incident or major incident management, not an immediate technical next step for confirmation.
  • D. Blocking is a containment action, but it's premature without verifying the nature of the traffic.

Incident Analysis & Validation

The process of thoroughly examining collected data to confirm the nature, scope, and impact of a potential security incident before proceeding with containment.

  • Aims to reduce false positives.
  • Involves reviewing logs, network traffic, system artifacts.
  • Crucial before implementing containment measures.

Memory trick: Analyze before you act!

More Security Operations questions