nerdexam
CompTIA

SY0-501 · Question #464

An incident response manager has started to gather all the facts related to a SIEM alert showing multiple systems may have been compromised. The manager has gathered these facts: The breach is…

The correct answer is D. Identification. The manager is in the Identification phase, actively gathering facts about the scope and nature of the incident before taking remediation action.

Submitted by renata2k· Mar 4, 2026Security operations

Question

An incident response manager has started to gather all the facts related to a SIEM alert showing multiple systems may have been compromised. The manager has gathered these facts:

The breach is currently indicated on six user PCs One service account is potentially compromised Executive management has been notified In which of the following phases of the IRP is the manager currently working?

Options

  • ARecovery
  • BEradication
  • CContainment
  • DIdentification

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    11% (3)
  • D
    78% (21)

Why each option

The manager is in the Identification phase, actively gathering facts about the scope and nature of the incident before taking remediation action.

ARecovery

Recovery involves restoring systems to normal operation after the threat has been eradicated, which has not yet occurred in this scenario.

BEradication

Eradication involves removing the root cause of the incident (e.g., deleting malware, disabling compromised accounts), but the manager is still assessing scope rather than removing threats.

CContainment

Containment involves actively limiting the spread of the incident (e.g., isolating affected systems), but the manager is still in the fact-gathering stage, not yet taking containment actions.

DIdentificationCorrect

The Identification phase involves detecting, analyzing, and documenting the scope of an incident - determining what systems are affected, what accounts may be compromised, and notifying stakeholders. The manager is still gathering facts (six PCs, one service account, executive notification) rather than taking action to stop or remove the threat, which are hallmarks of later phases.

Concept tested: Incident response plan phases and identification

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident response#IRP phases#identification#SIEM

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice