During the identification phase of the PICERL incident response cycle, a security analyst receives an alert for unusual login activity. What is the PRIMARY objective of this phase?
Select an answer to reveal the explanation.
Short Explanation
Here's the deal — c is correct because the Identification phase focuses on confirming whether an event is a true incident, characterizing its nature, and determining initial scope. This analysis drives the decision to escalate to subsequent phases.
Full Explanation
C is correct because the Identification phase focuses on confirming whether an event is a true incident, characterizing its nature, and determining initial scope. This analysis drives the decision to escalate to subsequent phases. A is wrong because removing files and restoring systems occurs in the Eradication and Recovery phases. B is wrong because isolation is the Containment phase. D is wrong because documentation and lessons learned are the Post-Incident Activity phase.