An EDR alert reports a suspicious process on a hybrid file server. Before the analyst reviews it, which SOAR action best improves the alert's context?
Select an answer to reveal the explanation.
Short Explanation
Think of SOAR enrichment like putting the case notes on the analyst's desk before they open the file. You want intel, asset, and identity context first, not a ticket or a heavy scan that stalls triage. Don't confuse workflow creation with enrichment.
Full Explanation
SOAR enrichment is a pre-review context layer that pulls from threat intelligence, CMDB or asset inventory, and identity sources to attach known indicators, business criticality, owner, and user account details to an alert. This matters because analysts triage by likelihood and impact; a suspicious process on a domain controller or high-value file server, matched to a known malicious hash or anomalous login, is prioritized differently than the same process on a low-value workstation. A ticketing action merely moves the alert into a queue and preserves the analyst's workload without adding investigative meaning. Automatic blocking can be appropriate after containment policy or confidence thresholds are met, but it skips the enrichment step and may disrupt a legitimate business process. A full system scan and quarantine are containment or investigation actions that consume time and resources; they are better triggered after enrichment or analyst review confirms sufficient risk. Exam caveat: SOAR and SIEM can both normalize data, but the tested distinction is automated contextual enrichment before human triage, not downstream response execution. Operational check: confirm the playbook queries threat intel, asset inventory, and identity services and writes the returned fields back to the case before assignment.