In this process the Auditor has to create an Audit session (A session is a logical grouping of applications and audits). By doing so the Auditor is "identifying" the various operating systems and databases available on the network that have to be audited to explore potential vulnerabilities that they might possess . This is done by providing "a host name" or by providing "a single" or "a range" of I.P addresses.