Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsEasy

A Security Operations Center (SOC) analyst is investigating a suspected malware infection on an internal workstation. The analyst has identified the malicious process and its associated files. What is the next logical step in the incident response process after identification?

  1. AEradication of the malware from the system.
  2. BPost-incident analysis and reporting.
  3. CRecovery of the system to a clean state.
  4. DContainment of the infected workstation to prevent further spread.
Show answer & explanation

Correct answer: D. Containment of the infected workstation to prevent further spread.

After identifying an incident, the immediate next step is containment to limit the damage and prevent the spread of the attack. Eradication, recovery, and post-incident analysis follow containment.

Why the other options are wrong

  • A. Eradication comes after containment, once the spread has been limited.
  • B. Post-incident analysis is the final phase, conducted after the incident has been resolved.
  • C. Recovery is performed after eradication, to restore affected systems to normal operation.

Incident Containment

The process of isolating an infected or compromised system or network segment to prevent an incident from spreading further and causing more damage.

  • Limits the scope of an attack.
  • Prevents lateral movement of attackers.
  • Can be short-term or long-term.

Memory trick: I C E R R L: I See Every Risky, Response-Driven Loop.

More Security Operations questions