The housing authority wants a documented check that account-takeover content is actually usable. What is the correct sequence?
Select an answer to reveal the explanation.
Short Explanation
Catalog, ingredients, pantry check, then the dashboard. SSE names the account-takeover use case and the sourcetypes it needs; ES confirms those sources are really there; the Security Domain view is the last look. Do not enable everything first and ask questions later.
Full Explanation
The data-source workflow is use-case-driven: choose the content in Security Essentials, read its required sourcetypes, verify collection and CIM mapping in Enterprise Security, then use the matching Security Domain dashboard as a live sanity check. Inventing sourcetypes, enabling all detections blindly, or replacing the assessment with Core dashboard XML skips the prerequisite check. That sequence is how a civic SOC proves a use case is usable.