During the identification phase of the PICERL incident response cycle, a security analyst receives an alert for unusual login activity. What is the PRIMARY objective of this phase?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — c is correct because the Identification phase focuses on confirming whether an event is a true incident, characterizing its nature, and determining initial scope. This analysis drives the decision to escalate to subsequent phases.
Full explanation below image
Full Explanation
C is correct because the Identification phase focuses on confirming whether an event is a true incident, characterizing its nature, and determining initial scope. This analysis drives the decision to escalate to subsequent phases. A is wrong because removing files and restoring systems occurs in the Eradication and Recovery phases. B is wrong because isolation is the Containment phase. D is wrong because documentation and lessons learned are the Post-Incident Activity phase.