An EDR alert flags suspicious PowerShell on a laptop used by a finance user. You need to decide whether this is an incident or a benign admin task. Which identification step should you take first?
Select an answer to reveal the explanation.
Short Explanation
Think of triage like checking the guest list before calling security: who was on the host, when it happened, and what else lit up? You don't need to isolate first; you need to see if the alert fits a real pattern or a known admin task. Overreacting burns response capacity, so correlate before you declare.
Full Explanation
Identification in incident response is about confirming whether an alert represents a real incident and how far it extends. The fastest way to scope an endpoint alert is to correlate it with the affected user, host, time window, and related alerts already in the SIEM or SOAR queue. That context shows whether the activity is isolated, part of a broader pattern, or a legitimate administrative task, letting the analyst avoid unnecessary containment. Escalating and isolating immediately may contain a true compromise, but it skips the scoping step and can disrupt business systems when the alert is benign. Running a full antivirus scan is a verification activity that can take time and does not answer whether other hosts, users, or alerts are involved. Searching threat intelligence feeds can enrich the alert, but it does not establish internal scope; a malicious indicator still does not prove this endpoint is part of the same incident. Exam caveat: CompTIA expects the analyst to use telemetry and correlated events to identify incidents before jumping to containment. Operational check: Query the SIEM for the same user, host, and time window, then attach any matching alerts to the ticket before declaring an incident.