A SOC prepares for ransomware across hybrid endpoints. During a live alert, analysts struggle to identify the first malicious process because endpoint visibility is inconsistent. Which preparation activity most improves incident identification?
Select an answer to reveal the explanation.
Short Explanation
Think of EDR as your endpoint's live camera; without process telemetry, you're guessing after the fact. Longer log retention helps you replay history, but it won't spot the first bad process faster. Deploy the sensors first, then keep the tape long enough to investigate.
Full Explanation
Preparation activities reduce friction by making evidence available at the moment an incident is suspected. EDR agents that collect process, network, and file telemetry give analysts immediate context: parent-child relationships, command lines, and lateral movement indicators. This directly improves incident identification because the analyst can distinguish benign administrative activity from malicious behavior while the event is still unfolding. Extending SIEM log retention supports investigation, hunting, and timeline reconstruction, but it does not create the endpoint visibility needed to recognize the initial malicious process. Publishing an incident response plan with contacts and severity definitions is essential for coordination and escalation, yet it is a governance artifact rather than a detection control. Running tabletop exercises improves readiness and communication, but it does not generate telemetry or make a live alert more identifiable. Exam caveat: CompTIA often separates preparation that improves detection from preparation that improves response efficiency. Operational check: Confirm that EDR coverage matches the asset inventory and that process, network, and file telemetry are retained according to policy.