nerdexam
Palo_Alto_Networks

PCCET · Question #55

In SecOps, what are two of the components included in the identify stage? (Choose two.)

The correct answer is A. Initial Research C. Content Engineering. In the SecOps lifecycle, the 'Identify' stage is focused on understanding threats and building detection capabilities. 'Initial Research' involves gathering intelligence about threats, adversary tactics, and vulnerabilities relevant to the organization. 'Content Engineering'…

Submitted by tunde_lagos· Apr 18, 2026Security Operations (SOC)

Question

In SecOps, what are two of the components included in the identify stage? (Choose two.)

Options

  • AInitial Research
  • BChange Control
  • CContent Engineering
  • DBreach Response

How the community answered

(58 responses)
  • A
    88% (51)
  • B
    5% (3)
  • D
    7% (4)

Explanation

In the SecOps lifecycle, the 'Identify' stage is focused on understanding threats and building detection capabilities. 'Initial Research' involves gathering intelligence about threats, adversary tactics, and vulnerabilities relevant to the organization. 'Content Engineering' involves creating and tuning detection content - such as correlation rules, SIEM queries, and IDS signatures - to identify those threats in the environment. 'Change Control' is an IT operations/ITSM process for managing changes to systems and is not part of the SecOps identify stage. 'Breach Response' belongs to the response/remediation stage of the SecOps lifecycle.

Topics

#SecOps processes#Identify stage#Content engineering#Incident identification

Community Discussion

No community discussion yet for this question.

Full PCCET Practice