In the Identification phase, what triggers it and what does it entail?

Prepare for the SANS FOR508 Exam. Use flashcards and multiple-choice questions, each with hints and explanations. Maximize your readiness for the test!

Multiple Choice

In the Identification phase, what triggers it and what does it entail?

Explanation:
An Identification phase is triggered when an alert or detection of suspicious activity is received and needs to be validated. It entails confirming that the event is actually an incident, gathering evidence, and assessing the severity and scope—what systems are affected, how broad the impact is, and the time window involved. This triage determines how to escalate and what containment actions might be required. Actions like immediate eradication, rebuilding systems, or enterprise-wide password resets belong to later response steps, not the identification trigger or its core activities.

An Identification phase is triggered when an alert or detection of suspicious activity is received and needs to be validated. It entails confirming that the event is actually an incident, gathering evidence, and assessing the severity and scope—what systems are affected, how broad the impact is, and the time window involved. This triage determines how to escalate and what containment actions might be required. Actions like immediate eradication, rebuilding systems, or enterprise-wide password resets belong to later response steps, not the identification trigger or its core activities.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy