A SOC analyst receives an alert that a user downloaded and executed a suspicious file. To decide containment, the analyst needs host-level process, file, and network context before relying on centralized correlation. Which telemetry source should be queried first?
Select an answer to reveal the explanation.
Short Explanation
Think of EDR as a camera on the workstation, while the SIEM is the security office wall of monitors. If you need to see what process wrote the file and where it connected, you check the endpoint agent first, not the aggregated logs. The trap is assuming centralized visibility equals detailed host context.
Full Explanation
Endpoint detection and response agents are installed directly on hosts and collect process creation, file access, binary hashes, registry changes, and outbound network connections. When containment depends on knowing which process opened a suspicious file and what it touched locally, the agent telemetry provides the authoritative host-level context. A SIEM collector aggregates and normalizes events from many systems, but it is not inherently a source of detailed endpoint activity unless the endpoint agent has already forwarded those records; it is better suited for correlation across sources. NetFlow records describe network conversations using source and destination addresses, ports, protocol, timing, and volume, but they contain no local process, file, or command-line context. Proxy access logs can identify web requests, URLs, user agents, and user attribution, yet they do not reveal what executable ran on the host or which files it modified. Exam caveat: match the requested detail to the telemetry source that actually captures it, rather than choosing the most centralized tool. Operational check: retrieve the endpoint agent process tree, file hash, and connection list for the affected host, then pivot to the SIEM for lateral movement or broader impact.