An organization wants to implement a Security Operations Center maturity model. Which capability represents the highest maturity level?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because the highest SOC maturity levels involve proactive threat hunting (finding attackers before automated tools alert) and adversary simulation/purple teaming (continuously validating and improving detection controls), requiring deep expertise and sophisticated analytical capabilities. A is wrong because reactive monitoring is the lowest maturity level — simply responding to automated alerts.
Full explanation below image
Full Explanation
B is correct because the highest SOC maturity levels involve proactive threat hunting (finding attackers before automated tools alert) and adversary simulation/purple teaming (continuously validating and improving detection controls), requiring deep expertise and sophisticated analytical capabilities. A is wrong because reactive monitoring is the lowest maturity level — simply responding to automated alerts. C is wrong because log collection is a foundational capability required at the lowest maturity levels. D is wrong because SIEM-ticketing integration is a basic operational efficiency improvement, not an advanced capability.