A security analyst receives an alert that a workstation's antivirus detected and quarantined a known trojan. The endpoint is still running and the user reports no unusual behavior. According to the SANS six-step incident handling process, which phase is the analyst currently in?
Identification is the phase where an event is confirmed as an incident and its scope is assessed. The antivirus alert and quarantine confirmation constitute detection and initial validation of a real security event. The analyst has not yet contained, eradicated, or recovered anything, so Identification is the correct phase according to the SANS PICERL model.
Why this answer
The SANS incident handling process begins with Preparation, followed by Identification, Containment, Eradication, Recovery, and Lessons Learned. When an alert fires and an analyst validates that a genuine security event has occurred, the activity maps to Identification. No containment, eradication, or recovery actions have been described, so the scenario sits squarely in the Identification phase.
Exam trap
The trap here is confusing the antivirus's automatic quarantine action with the Eradication phase, when quarantine is merely part of detecting and validating the incident.