A school-district SOC sees suspicious process creation on a teacher laptop and a matching unusual sign-in. Which investigative approach strengthens the conclusion?
Select an answer to reveal the explanation.
Short Explanation
One sensor is a clue; two sensors telling the same story is a case. Pairing EDR process telemetry with auth logs shows whether that teacher laptop malware run lined up with a weird sign-in. Tossing identity evidence or reimaging first throws away the timeline.
Full Explanation
Correlating endpoint detection and response telemetry with authentication logs links host execution to identity activity, producing stronger investigative conclusions than either source alone. Dismissing alerts without correlation, destroying auth evidence, or reimaging before capture reduces fidelity. Multi-source correlation is a core investigation practice for municipal and education SOCs.