Explanation: Security Operations (SecOps) is the process of coordinating and aligning security teams and IT teams to improve the security posture of an organization. SecOps involves implementing and maintaining security controls, technologies, policies, and procedures to protect the organization from cyber threats and incidents. When dealing with a known attack, SecOps must take the following action: document, monitor, and track the incident. This action is important because it helps SecOps to:
•Record the details of the attack, such as the source, target, impact, timeline, and response actions.
•Monitor the status and progress of the incident response and recovery efforts, as well as the ongoing threat activity and indicators of compromise.
•Track the performance and effectiveness of the security controls and technologies, as well as the lessons learned and improvement opportunities. References:
•Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)
•6 Incident Response Steps to Take After a Security Event - Exabeam
•Dealing with Cyber Attacks–Steps You Need to Know | NIST