A SOC playbook automatically enriches an alert, isolates an endpoint, opens a ticket, and posts a notification without analyst clicks. Each step is already automated, but the analyst notices the steps are sequenced and share data across EDR, ticketing, and notification systems. Which capability best describes this cross-system coordination?
Select an answer to reveal the explanation.
Short Explanation
Think of it like this: automation is one trained dog fetching the ball, while orchestration is the handler sequencing the whole show. You already have each task running, so the real question is who coordinates them across EDR, ticketing, and notifications. Don't let “automated task execution” fool you—that's just a single trick, not the whole workflow.
Full Explanation
Orchestration is the capability that coordinates multiple automated tasks across disparate systems so they execute in a defined sequence and pass context from one step to the next. When several already-automated actions are chained together, the value comes from sequencing, data handoff, and failure handling across systems, not merely from removing clicks for one task. This is different from automation, which only means a single task can run without manual effort. Standalone scripting may implement one step, but it does not describe the coordinated, cross-system workflow. Manual escalation is a human handoff, not an automated coordination capability, and it breaks the efficiency goal. A playbook can be the artifact that contains the orchestration, but the concept being tested is the coordination layer itself, not the document or script that stores the steps. Exam caveat: when a stem lists several integrated systems, choose orchestration rather than automation unless it clearly describes one isolated action. Operational check: review a high-volume playbook and confirm each step has a defined trigger, input, output, and failure path across the involved systems.