Which combination of SOC tooling would provide comprehensive detection, investigation, and response capability for a large enterprise?
Correct Answer: A SIEM for centralized log aggregation and correlation, EDR for detailed endpoint telemetry and response actions, and a SOAR platform for automating and orchestrating validated, tested response playbooks
Explanation: A SIEM for correlation, EDR for endpoint telemetry/response, and a validated SOAR platform together provide comprehensive capability, unlike a SIEM alone with no EDR/SOAR, a SOAR platform with no underlying data, siloed EDR with no SIEM correlation, untested SOAR playbooks in production, or deploying all three without integration.
Correct Answer: A SIEM for centralized log aggregation and correlation, EDR for detailed endpoint telemetry and response actions, and a SOAR platform for automating and orchestrating validated, tested response playbooks
Explanation: A SIEM for correlation, EDR for endpoint telemetry/response, and a validated SOAR platform together provide comprehensive capability, unlike a SIEM alone with no EDR/SOAR, a SOAR platform with no underlying data, siloed EDR with no SIEM correlation, untested SOAR playbooks in production, or deploying all three without integration.