skip to content

EDR, SOAR & Defensive Tooling Classes

What each defensive tooling class records, decides and does unattended: sensors, risk scores, data-loss engines, deception, response automation. Interviewers check you pick a class, not a brand.

on this pageshow

explore

questions

page 2 of 2

Your EDR console records a token-authenticated agent uninstall on a production Linux host. How do you decide whether an adversary did it?

level: seniorimportance: should knowfreq 60%

basics

~20 s

Treat it as an intrusion until proven otherwise. Tie the uninstall to a change record and an operator, work out where the token came from, and reconstruct the host from records other than the agent's.

open as a page

An adversary fires 300 near-identical alerts so your response platform hits its API rate limit — how do you stop real containment being dropped?

level: seniorimportance: should knowfreq 34%

basics

~10 s

Give containment actions a reserved quota lane ahead of enrichment, and make a rate-limited containment action halt and page rather than be skipped. Treat the flood as a diversion and hunt that window.

open as a page

Sales says your data-loss block stops legitimate customer exports daily - do you demote the policy to monitor?

level: principalimportance: should knowfreq 38%

basics

~20 s

Sometimes yes, and that is a legitimate outcome rather than a defeat - but only after separating false positives from benign true positives, and only with the residual risk accepted by a named business owner rather than by the security team.

open as a page

Auto-isolation cut off the CFO's laptop mid-board-meeting and the CIO now wants it disabled estate-wide. What do you argue?

level: principalimportance: should knowfreq 41%

basics

~20 s

Refuse the on-or-off framing. Make the exchange rate visible - what automation contained last quarter and how fast, against the cost of this one action - then propose scope: softer actions on executive and production hosts, a named reversal owner.

open as a page

Half your response playbooks depend on connectors other teams own — who is accountable when a token rotation silently disarms containment?

level: principalimportance: should knowfreq 26%

basics

~20 s

Accountability for the containment capability stays with security, since only security knows it is critical. You cannot own every other team's API, so buy detection instead: exercise each containment path end to end on a schedule.

open as a page

All five SOC analysts hold standing EDR execute-everywhere rights. How do you scope that without losing 03:00 speed?

level: principalimportance: should knowfreq 36%

basics

~20 s

Split the verbs by blast radius and reversibility. Leave reads and single-host isolation standing; require a second named person, just in time, for fleet-wide execution and anything that removes visibility. Then staff the gate with the on-call pair, and measure how often break-glass is used.

open as a page

How could an adversary deliberately trip your automated account-disable rule to lock your own responders out?

level: seniorimportance: nice to knowfreq 28%

basics

~20 s

By planting whatever artefact the rule matches under the accounts recovery depends on - break-glass, backup and SOC admin accounts - so the platform disables them for him. Automated containment becomes his denial-of-service tool, at machine speed.

open as a page

Your EDR vendor flags unfamiliar console API use; how do you separate your SOC's commands from an intruder's?

level: seniorimportance: nice to knowfreq 31%

basics

~20 s

Reconcile the console's own per-command history against your case records and roster: every legitimate action should tie to an open case and a rostered operator. Then sort by principal, session and source address, and treat anything unreconciled as a lead to test, not a conclusion.

open as a page

HR asks you to justify a 92 UEBA risk score to the employee it belongs to - what do you say?

level: principalimportance: nice to knowfreq 29%

basics

~20 s

Defend the records, not the number. Show the specific logon, VPN and file-access events and what each was compared against, and state that the score only ranks a queue: it is not evidence and carries no finding.

open as a page

A genuine supplier invoice sat in phishing quarantine six hours. Who should hold release authority?

level: principalimportance: nice to knowfreq 29%

basics

~20 s

Split authority by verdict class, not by team politics. Low-confidence spam and bulk can be user-releasable; a high-confidence phishing verdict should stay administrator-released with a request path. The six hours is an adjudication-workflow problem, not a reason to weaken the filter.

open as a page

Do you fund a fourth security console after three products saw the intrusion and none stopped it?

level: principalimportance: nice to knowfreq 41%

basics

~20 s

Not until you know which stage failed: telemetry missing, no rule, nobody acted, or the response never landed. Only the first is a control-class gap a new product can fill; the rest are configuration, ownership or contract problems.

open as a page

In an EDR bake-off, how would you falsify a vendor's claim that behavioural AI convicts fileless attacks?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

You cannot inspect the model, so test its output. Execute the behaviour yourself in the trial tenant under the policy you would really deploy, and measure what got through and the damage before the action — not alert counts.

open as a page

How do you stop IT from deleting your decoy accounts without letting an adversary discover the list?

level: principalimportance: nice to knowfreq 30%

basics

~10 s

Protect decoys with controls rather than knowledge: deny-delete permissions, alerting on their container, attributes hygiene policy will not select. Keep the written record small, owned, and outside what an intruder enumerates.

open as a page

A vendor voids support if you install the EDR agent and the platform team refuses it on CPU grounds. How do you design around that?

level: principalimportance: nice to knowfreq 36%

basics

~20 s

Stop arguing about the agent and buy visibility elsewhere: mandatory log forwarding, network chokepoints, jump-host-only administration with recorded sessions, and segmentation. Then record the gap as an owned, dated risk acceptance and make agent support a procurement requirement.

open as a page

showing 31–44 of 44