Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsHard

A security analyst is investigating an alert indicating suspicious outbound network traffic from an internal server to an unknown external IP address on TCP port 4444. Reviewing the server's purpose, it should only communicate internally. The analyst suspects a potential command-and-control (C2) channel has been established. Which of the following is the most immediate and critical next step in containing this potential incident?

  1. ANotify law enforcement and legal counsel about the potential breach.
  2. BCollect forensic images of the compromised server for later analysis.
  3. CBlock the destination external IP address at the perimeter firewall.
  4. DRestore the server from a known good backup.
Show answer & explanation

Correct answer: C. Block the destination external IP address at the perimeter firewall.

The most immediate and critical next step in containment is to stop the active communication channel. Blocking the destination external IP address at the perimeter firewall will sever the suspected C2 communication, preventing further data exfiltration or remote control, without immediately disrupting internal services or destroying potential evidence on the server itself. While other options are important, they are either premature or less immediate for active containment.

Why the other options are wrong

  • A. Notifying law enforcement/legal counsel is important for post-incident activity and compliance, but not the immediate technical containment step.
  • B. Forensic imaging is crucial but typically follows initial containment to preserve evidence; it doesn't stop active communication.
  • D. Restoring from backup is part of eradication and recovery, which comes after containment, and might destroy evidence of the intrusion.

Incident Containment

The phase of incident response aimed at limiting the scope and impact of a security incident.

  • Focuses on stopping the spread of the attack.
  • Can involve isolating systems, blocking malicious IPs, or disabling accounts.
  • Must be balanced with evidence preservation and business continuity.

Memory trick: When the alarm rings, first cut the wires to stop the spread.

More Security Operations questions