EDR, SOAR & Defensive Tooling Classes
What each defensive tooling class records, decides and does unattended: sensors, risk scores, data-loss engines, deception, response automation. Interviewers check you pick a class, not a brand.
on this pageshowhide
explore
- What the Sensor Records16 questions
- EDR Event Streams3 questions
- From Signatures to Behaviour4 questions
- Agent Blind Spots4 questions
- Canaries and Honey Accounts5 questions
- Controls That Decide Alone16 questions
- User Risk Scores4 questions
- Watching Data Leave4 questions
- Three Consoles, One Event4 questions
- Quarantine, Rewrite, Claw Back4 questions
- Acting Without You12 questions
- Brittle Response Automation4 questions
- Containment Without a Human4 questions
- Privilege the Tooling Holds4 questions
questions
page 2 of 2Your EDR console records a token-authenticated agent uninstall on a production Linux host. How do you decide whether an adversary did it?
basics
~20 sTreat it as an intrusion until proven otherwise. Tie the uninstall to a change record and an operator, work out where the token came from, and reconstruct the host from records other than the agent's.
An adversary fires 300 near-identical alerts so your response platform hits its API rate limit — how do you stop real containment being dropped?
basics
~10 sGive containment actions a reserved quota lane ahead of enrichment, and make a rate-limited containment action halt and page rather than be skipped. Treat the flood as a diversion and hunt that window.
Sales says your data-loss block stops legitimate customer exports daily - do you demote the policy to monitor?
basics
~20 sSometimes yes, and that is a legitimate outcome rather than a defeat - but only after separating false positives from benign true positives, and only with the residual risk accepted by a named business owner rather than by the security team.
Auto-isolation cut off the CFO's laptop mid-board-meeting and the CIO now wants it disabled estate-wide. What do you argue?
basics
~20 sRefuse the on-or-off framing. Make the exchange rate visible - what automation contained last quarter and how fast, against the cost of this one action - then propose scope: softer actions on executive and production hosts, a named reversal owner.
Half your response playbooks depend on connectors other teams own — who is accountable when a token rotation silently disarms containment?
basics
~20 sAccountability for the containment capability stays with security, since only security knows it is critical. You cannot own every other team's API, so buy detection instead: exercise each containment path end to end on a schedule.
All five SOC analysts hold standing EDR execute-everywhere rights. How do you scope that without losing 03:00 speed?
basics
~20 sSplit the verbs by blast radius and reversibility. Leave reads and single-host isolation standing; require a second named person, just in time, for fleet-wide execution and anything that removes visibility. Then staff the gate with the on-call pair, and measure how often break-glass is used.
How could an adversary deliberately trip your automated account-disable rule to lock your own responders out?
basics
~20 sBy planting whatever artefact the rule matches under the accounts recovery depends on - break-glass, backup and SOC admin accounts - so the platform disables them for him. Automated containment becomes his denial-of-service tool, at machine speed.
Your EDR vendor flags unfamiliar console API use; how do you separate your SOC's commands from an intruder's?
basics
~20 sReconcile the console's own per-command history against your case records and roster: every legitimate action should tie to an open case and a rostered operator. Then sort by principal, session and source address, and treat anything unreconciled as a lead to test, not a conclusion.
HR asks you to justify a 92 UEBA risk score to the employee it belongs to - what do you say?
basics
~20 sDefend the records, not the number. Show the specific logon, VPN and file-access events and what each was compared against, and state that the score only ranks a queue: it is not evidence and carries no finding.
A genuine supplier invoice sat in phishing quarantine six hours. Who should hold release authority?
basics
~20 sSplit authority by verdict class, not by team politics. Low-confidence spam and bulk can be user-releasable; a high-confidence phishing verdict should stay administrator-released with a request path. The six hours is an adjudication-workflow problem, not a reason to weaken the filter.
Do you fund a fourth security console after three products saw the intrusion and none stopped it?
basics
~20 sNot until you know which stage failed: telemetry missing, no rule, nobody acted, or the response never landed. Only the first is a control-class gap a new product can fill; the rest are configuration, ownership or contract problems.
In an EDR bake-off, how would you falsify a vendor's claim that behavioural AI convicts fileless attacks?
basics
~20 sYou cannot inspect the model, so test its output. Execute the behaviour yourself in the trial tenant under the policy you would really deploy, and measure what got through and the damage before the action — not alert counts.
How do you stop IT from deleting your decoy accounts without letting an adversary discover the list?
basics
~10 sProtect decoys with controls rather than knowledge: deny-delete permissions, alerting on their container, attributes hygiene policy will not select. Keep the written record small, owned, and outside what an intruder enumerates.
A vendor voids support if you install the EDR agent and the platform team refuses it on CPU grounds. How do you design around that?
basics
~20 sStop arguing about the agent and buy visibility elsewhere: mandatory log forwarding, network chokepoints, jump-host-only administration with recorded sessions, and segmentation. Then record the gap as an owned, dated risk acceptance and make agent support a procurement requirement.
showing 31–44 of 44