An EDR/SIEM alert fires after 18 failed logon attempts to a service account from a maintenance host. The host is known to run a scheduled backup job, and no successful logon or lateral movement appears. Before deciding whether this is a reportable incident, what should the analyst do first?
Select an answer to reveal the explanation.
Short Explanation
Think of an alert like a smoke detector: a little steam from dinner doesn't always mean the kitchen is on fire. You still check the incident criteria before calling the fire department, because escalating noise wastes response time. The trap is treating every failed logon spike as reportable instead of validating it against policy.
Full Explanation
In incident response, identification is the step where the analyst determines whether observed activity meets the organization's predefined incident criteria, such as impact, severity, likelihood, and reporting thresholds. A failed-logon spike is a signal, not automatically an incident. By comparing the telemetry with the criteria, the analyst can decide whether to escalate, tune, or document a false positive while preserving evidence. Immediate escalation is wrong because brute-force indicators require context: no successful authentication, no lateral movement, and a known scheduled job reduce the likelihood of a reportable compromise. Closing it as false positive without criteria is wrong because failed logons can precede credential stuffing, spray, or account compromise, and policy may require review. Opening an incident for every authentication anomaly is wrong because incident creation consumes response capacity and obscures real events; alerts should be triaged against criteria first. Exam caveat: CompTIA expects triage before escalation, not automatic escalation of all alerts. Operational check: review the SIEM alert, confirm the source host and scheduled task, then record whether the incident criteria are met or not.