Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsEasy

A Security Operations Center (SOC) analyst is reviewing network traffic logs and observes a sudden, significant increase in outbound data from an internal server that typically has low outbound traffic. The destination IP addresses are varied and appear to be external. Which phase of the incident response process is the analyst currently engaged in?

  1. AIdentification
  2. BContainment
  3. CEradication
  4. DRecovery
Show answer & explanation

Correct answer: A. Identification

The analyst is observing unusual activity and trying to determine if it constitutes an incident. This initial phase of recognizing and validating potential security events is known as identification.

Why the other options are wrong

  • B. Containment aims to limit the scope and impact of an incident once it has been identified.
  • C. Eradication involves removing the cause of the incident and restoring affected systems to a clean state.
  • D. Recovery focuses on restoring affected systems and services to normal operation.

Incident Identification

The first phase of incident response, focused on detecting and validating potential security events that may indicate a breach or compromise.

  • Involves monitoring systems and networks for anomalies.
  • Aims to confirm if an event is indeed an incident.
  • Precedes containment and eradication.

Memory trick: I Can't Eat Raw Carrots

More Security Operations questions