Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsMedium
During an incident response investigation, a security analyst discovers that a critical server has been compromised and data exfiltration has occurred. The incident response plan specifies that external legal counsel and regulatory bodies must be notified. In which phase of the incident response lifecycle would these notifications typically take place?
- APreparation
- BContainment, Eradication, & Recovery
- CPost-Incident Activity
- DIdentification & Analysis
Show answer & explanationAnswer & explanation
Correct answer: C. Post-Incident Activity
Notifications to external parties like legal counsel and regulatory bodies, especially concerning data breaches and exfiltration, are typically part of the Post-Incident Activity phase. This phase focuses on lessons learned, reporting, and fulfilling legal/compliance obligations after the technical resolution.
Why the other options are wrong
- A. Preparation involves proactive measures before an incident, not notifications during or after.
- B. This phase focuses on stopping the incident, removing the threat, and restoring services, not external notifications.
- D. Identification and Analysis is about detecting and understanding the incident, not external communication.
Post-Incident Activity
The final phase of incident response, focusing on review, documentation, reporting, and lessons learned.
- Includes creating a 'lessons learned' document.
- Involves formal reporting to management and external stakeholders.
- Ensures compliance with legal and regulatory notification requirements.
Memory trick: IR is like a fire drill: prepare, detect, fight, then review.