A SOC manager asks an analyst to show whether recent playbook improvements are making the team faster. The analyst has ticket timestamps, alert-generation times, and containment times. Which metric set should be reported to evaluate detection and resolution effectiveness?
Select an answer to reveal the explanation.
Short Explanation
Think of it like a race clock: you need to know when the fire was first spotted and when it was finally out. MTTD and MTTR give you those two checkpoints, so you can tell if new playbooks actually speed the team up. If you only count closed tickets or false positives, you're measuring volume, not speed.
Full Explanation
MTTD and MTTR are operational clocks that answer whether the SOC is getting faster. MTTD is measured from alert generation, or visible compromise evidence, to analyst recognition. MTTR is measured from that recognition to containment, eradication, and recovery. In a hybrid SOC, these values connect SIEM timestamps, EDR events, ticket acknowledgment, and containment status, letting a manager compare performance before and after playbook changes. A false positive rate and closed-ticket count can show alert quality and workload throughput, but not how quickly a real incident was found and stopped. Mean time between failures and patch success rate are reliability or maintenance measures; they may reduce incident volume yet do not measure response speed. Escalation percentage and shift utilization describe routing and staffing pressure, not elapsed time from alert creation to containment. Exam caveat: choose the metric that matches the requested outcome, because speed metrics and quality metrics are often mixed. Operational check: pull alert-generation, analyst acknowledgment, and containment timestamps, then calculate average MTTD and MTTR by incident category.