Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsMedium

A SOC analyst receives an alert from the SIEM indicating a successful login to a critical production server from an IP address associated with a known malicious botnet. The analyst immediately confirms the alert is a true positive. What is the most appropriate next step in the incident response process, following the identification of this confirmed incident?

  1. AInitiate a full forensic investigation of the server.
  2. BUpdate the SIEM rules to prevent similar future attacks.
  3. CContain the threat by isolating the compromised server.
  4. DEradicate the malware from the server and restore services.
Show answer & explanation

Correct answer: C. Contain the threat by isolating the compromised server.

After identifying and confirming an incident, the immediate priority is containment to limit further damage or spread. Isolating the compromised server prevents the attacker from causing more harm, exfiltrating data, or pivoting to other systems. Forensic investigation, eradication, and recovery follow this critical containment step.

Why the other options are wrong

  • A. Forensic investigation is part of analysis and post-containment; it doesn't stop the active threat.
  • B. Updating SIEM rules is a post-incident activity (lessons learned/preparation) and doesn't address the ongoing incident.
  • D. Eradication and recovery occur after containment; attempting these prematurely without containment can lead to re-infection.

Incident Response Flow

The structured process followed to manage and resolve a cybersecurity incident, typically starting with preparation and ending with post-incident activities.

  • NIST SP 800-61 Rev. 2 defines a common framework.
  • Phases: Preparation, Identification, Containment, Eradication, Recovery, Post-Incident Activity.
  • Containment is critical after identification to limit impact.

Memory trick: Prepare, ID, Contain, Eradicate, Recover, Post-mortem (PICERL).

More Security Operations questions