Courseiva

GSEC Incident Handling and Response Practice Question

A security analyst receives an alert that a workstation's antivirus detected and quarantined a known trojan. The endpoint is still running and the user reports no unusual behavior. According to the SANS six-step incident handling process, which phase is the analyst currently in?

⚠ Common exam trap

Test-takers frequently confuse the antivirus's automatic quarantine action with the Eradication phase, when quarantine is merely part of detecting and validating the incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identification

The SANS incident handling process begins with Preparation, followed by Identification, Containment, Eradication, Recovery, and Lessons Learned. When an alert fires and an analyst validates that a genuine security event has occurred, the activity maps to Identification. No containment, eradication, or recovery actions have been described, so the scenario sits squarely in the Identification phase.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Identification

    Why this is correct

    Identification is the phase where an event is confirmed as an incident and its scope is assessed. The antivirus alert and quarantine confirmation constitute detection and initial validation of a real security event. The analyst has not yet contained, eradicated, or recovered anything, so Identification is the correct phase according to the SANS PICERL model.

  • ✗

    Eradication

    Why it's wrong here

    Eradication is the removal of the malicious component and the root cause. While the antivirus quarantined the trojan, the analyst has not confirmed removal of persistence mechanisms or verified the root cause. The scenario describes detection, not the deliberate elimination of the threat, so Eradication is premature here.

  • ✗

    Containment

    Why it's wrong here

    Containment involves limiting the damage and preventing further spread, such as isolating the host from the network. The scenario states the endpoint is still running and no containment actions have been taken. The analyst is only validating the alert, so labeling this Containment skips the critical Identification step that precedes any containment action.

  • ✗

    Recovery

    Why it's wrong here

    Recovery focuses on restoring systems to normal operation and monitoring for recurrence. The endpoint was never taken offline or remediated, so there is nothing to recover. The analyst is still determining whether an incident occurred, which places the activity firmly in Identification rather than Recovery.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.