During an end-of-shift handoff in a SOC, an analyst leaves an active phishing investigation with one unresolved alert and a pending containment task. To preserve continuity, what should the outgoing analyst do first?
Select an answer to reveal the explanation.
Short Explanation
Think of a SOC handoff like passing a hot potato: if the next analyst can't see the status, open alerts, and next steps, the incident gets dropped. You don't fix it by emailing raw logs or making the new analyst start over—you put the context in the ticket. That's the simple process improvement that keeps shifts continuous.
Full Explanation
Shift handoffs succeed when the incoming analyst inherits a current, shared operational picture rather than a pile of raw data. A ticket or incident record that captures status, open alerts, pending actions, evidence locations, and next steps preserves continuity, supports triage, and reduces duplicate work. This is a process-control concept: the handoff artifact is the control that prevents loss of context when personnel change. Raw logs sent by email are not a handoff control because they lack interpretation, prioritization, and linkage to the case record; they can also create shadow copies outside the official timeline. Requiring the incoming analyst to rebuild context from dashboards wastes time, can miss actions already taken or agreed upon, and undermines consistent incident response. Escalating to redistribute the queue avoids the immediate responsibility but does not create continuity for the original incident; it may also fragment ownership and obscure accountability. Exam caveat: choose the answer that documents the incident state and pending work, not the answer that merely transfers data or reassigns the ticket. Operational check: before ending a shift, confirm the incident record shows current status, open alerts, completed actions, pending tasks, and evidence links.