GSEC Incident Handling and Response Practice Question
A security analyst receives an alert that a workstation's antivirus detected and quarantined a known trojan. The endpoint is still running and the user reports no unusual behavior. According to the SANS six-step incident handling process, which phase is the analyst currently in?
⚠ Common exam trap
Test-takers frequently confuse the antivirus's automatic quarantine action with the Eradication phase, when quarantine is merely part of detecting and validating the incident.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identification
The SANS incident handling process begins with Preparation, followed by Identification, Containment, Eradication, Recovery, and Lessons Learned. When an alert fires and an analyst validates that a genuine security event has occurred, the activity maps to Identification. No containment, eradication, or recovery actions have been described, so the scenario sits squarely in the Identification phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identification
Why this is correct
Identification is the phase where an event is confirmed as an incident and its scope is assessed. The antivirus alert and quarantine confirmation constitute detection and initial validation of a real security event. The analyst has not yet contained, eradicated, or recovered anything, so Identification is the correct phase according to the SANS PICERL model.
- ✗
Eradication
Why it's wrong here
Eradication is the removal of the malicious component and the root cause. While the antivirus quarantined the trojan, the analyst has not confirmed removal of persistence mechanisms or verified the root cause. The scenario describes detection, not the deliberate elimination of the threat, so Eradication is premature here.
- ✗
Containment
Why it's wrong here
Containment involves limiting the damage and preventing further spread, such as isolating the host from the network. The scenario states the endpoint is still running and no containment actions have been taken. The analyst is only validating the alert, so labeling this Containment skips the critical Identification step that precedes any containment action.
- ✗
Recovery
Why it's wrong here
Recovery focuses on restoring systems to normal operation and monitoring for recurrence. The endpoint was never taken offline or remediated, so there is nothing to recover. The analyst is still determining whether an incident occurred, which places the activity firmly in Identification rather than Recovery.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.