Triage BoardGet the app

Concept · Analysis tools

SIEM vs SOAR vs EDR (and XDR, UEBA)

A security information and event management (SIEM) system collects and correlates logs and raises the alert, security orchestration, automation, and response (SOAR) runs the playbook that acts on it, and endpoint detection and response (EDR) records and responds on the endpoint itself. Extended detection and response (XDR) stretches endpoint-style detection across network, cloud and email, and user and entity behavior analytics (UEBA) learns what normal looks like for each user and device. The CS0-004 exam names them in objectives 1.3 and 1.5, and the usual question describes a capability and asks which tool owns it. They belong to security analysis tools.

  • Exam code CS0-004
  • Tickets here 8

Five tools, five jobs

SIEM
Pulls logs from firewalls, servers, identity systems and applications, normalizes them, correlates events across sources and raises alerts. It also keeps the logs searchable for investigations and retention rules. Detection and context are its job; acting on the alert is not.
SOAR
Takes an alert and runs a playbook through other tools' APIs: enrichment lookups, ticket creation, blocking, quarantine, notifications. It depends on a SIEM, EDR or similar for the detection itself.
EDR
An agent on each host records processes, file and registry changes and network connections, detects by behavior as well as by signature, and lets you respond on that host: kill a process, isolate the machine, pull artifacts.
XDR
The EDR model widened: one product correlates telemetry from endpoint, network, cloud workloads and email, and responds across them.
UEBA
Builds a baseline for each user, host and service account and flags deviations, such as access at unusual hours or a sudden jump in data touched. The CS0-004 objectives list it under 1.3 with OpenUBA as the example.

One alert, four hands

EndpointEDR telemetrySIEMcorrelate, alertSOARrun playbookAnalystdecide, close
Telemetry flows up from the endpoint; the SIEM decides it matters, SOAR does the routine work, and a person makes the call.

Match the stem to the tool

The capability in the question decides the answer
The stem describesPickWhy the runner-up loses
Events from the proxy, VPN and domain controller tied into one timelineSIEMEDR sees one host at a time
An alert that triggers enrichment, a ticket and an account lock with no analyst involvedSOARA SIEM raises the alert; the hands-off action is SOAR's
A laptop cut off from the network while its process tree is preservedEDRA SIEM has no agent on the host
A phishing email linked to the endpoint it reached and the cloud sign-in that followedXDREDR alone stops at the endpoint
A service account reading far more records than its own historyUEBAA signature rule has nothing to match

The SIEM that respondsTrap

Many SIEM products now ship response buttons, and vendors blur the names on purpose. The exam keeps them apart. When a stem stresses automated, playbook-driven action across several tools, the answer is SOAR; when it stresses collecting and correlating logs from many sources, it is SIEM. Read the verb in the stem before the product names in the options.

Where each one sits in the objectives

Objective 1.3 of CySA+ CS0-004 ("use tools to determine malicious activity") lists the SIEM, EDR and XDR, and UEBA among the tools you should be able to read. Expect those as scenario questions: a dashboard, an alert or a host timeline, and a choice of what it proves.

SOAR sits in objective 1.5, under streamlining security operations with automation and orchestration, next to data enrichment and rule tuning. The automation and process improvement guide covers playbooks, APIs and webhooks in more depth.

One link between the two is worth keeping in mind. SOAR automates whatever the SIEM feeds it, so a noisy rule becomes a noisy playbook that locks accounts for no reason. That is why tuning comes before automation, and why the difference between false positives and false negatives matters for both tools.

For EDR, the angle the exam likes is visibility. Antivirus matches known files; EDR also records what processes did, which is how it catches attacks built from legitimate tools already on the machine.

Assign the tool

Name the tool that owns the capability, alert or dashboard described, the way a working security operations center (SOC) would split them.

Ticket 1 / 8

0 right

INC-001

An organization uses a monitoring system that can log security incidents and alert the IT team about potential threats. However, this system does not have the capability to automatically respond to or mitigate these threats. What type of system is being described?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: A SIEM collects and correlates logs and raises alerts, but acting on them automatically is the job of SOAR (or an IPS/EDR), which fits a system that logs and alerts but doesn't respond.
  2. BA honeypot is a decoy built to attract and study attackers; it doesn't monitor the organization's own systems and send them alerts.
  3. CA firewall enforces traffic rules by allowing or blocking traffic, which is itself a mitigating action, and it isn't a central incident logging and alerting system.
  4. DAn IPS can block traffic automatically, which is the capability the stem says this system lacks.

INC-002

Which security operations approach leverages automation to respond to security events without human intervention based on predefined playbooks?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ACI/CD automates building and deploying software, not responding to security events.
  2. BCorrect: SOAR runs predefined playbooks that carry out response steps automatically, without waiting for an analyst on routine events.
  3. CManual triage is the opposite of the approach described, because a person does the work.
  4. DA TIP collects and manages threat intelligence to enrich detections; it doesn't run response playbooks.

INC-003

Which of the following is used to detect unusual activities on endpoints?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: EDR records process, file, registry and network activity on each endpoint and flags unusual behavior there.
  2. BDLP watches data moving (email, uploads, USB) to stop sensitive data from leaking, not general unusual activity on endpoints.
  3. CA SIEM correlates logs from many sources centrally; it can use endpoint logs but isn't the endpoint-focused detection tool.
  4. DAn IDS usually watches network traffic for signatures or anomalies and does not see activity on the endpoint itself.

INC-004

In the context of endpoint security monitoring, what is the main advantage of using endpoint detection and response (EDR) tools compared to traditional antivirus software?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AEDR usually adds configuration and tuning work compared with basic antivirus instead of reducing it.
  2. BEDR records a lot of telemetry continuously, so it typically uses more endpoint resources than basic antivirus.
  3. CNo detection tool eliminates false positives, and behavior-based EDR alerts need tuning and triage.
  4. DCorrect: EDR records endpoint behavior and lets analysts investigate and respond, so it catches fileless and novel attacks that signature-based antivirus misses.

INC-005

Which security monitoring technique is most effective for detecting insider threats?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AA vulnerability assessment finds technical weaknesses in systems and does not look for misuse by people who already have legitimate access.
  2. BAnti-malware catches malicious code, but an insider often misuses legitimate tools and access with no malware at all.
  3. CCorrect: UEBA learns normal behavior for users and devices and flags deviations, such as unusual access or bulk downloads, which is how insider misuse usually shows itself.
  4. DPerimeter intrusion detection watches traffic at the network edge, while insiders are already inside and authorized.

INC-006

In a Security Information and Event Management (SIEM) system, which feature is primarily responsible for identifying patterns and anomalies from aggregated network logs?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ALog archiving stores events long term for retention and later investigation; it doesn't analyze them for patterns.
  2. BAggregation brings logs from many sources into one place, which correlation needs, but on its own it finds nothing.
  3. CCorrect: Correlation applies rules and analytics across the aggregated events to link related activity and surface patterns and anomalies.
  4. DAlerting notifies analysts after correlation has found something, so it is the output of the analysis instead of the analysis itself.

INC-007

A cybersecurity analyst needs a security information and event management (SIEM) tool to monitor the network activity and log files. Which of the following is NOT a SIEM tool?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Nessus is a vulnerability scanner that probes systems for weaknesses; it doesn't collect and correlate logs as a SIEM does.
  2. BLogRhythm is a SIEM platform that collects, correlates and alerts on log data.
  3. CSplunk is widely used as a SIEM (Splunk Enterprise Security) to collect and correlate logs.
  4. DIBM QRadar is a SIEM platform that collects, correlates and alerts on security events.

INC-008

A security operations team is implementing a new endpoint detection and response (EDR) solution. Which capability should be prioritized to most effectively detect fileless malware attacks?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AFileless malware runs in memory or through legitimate tools, so there is often no malicious file to hash.
  2. BCorrect: Fileless attacks live in memory and abuse legitimate tools such as PowerShell, so memory analysis and behavior monitoring are what reveal them.
  3. CDisk encryption verification protects data at rest and does nothing to detect malicious code running in memory.
  4. DApplication allowlisting is a preventive control, and fileless attacks usually abuse already-allowed binaries such as PowerShell, so it isn't the detection capability asked for.

Shift tally

0 / 0

Before you close this tab

  • SIEM correlates and alerts; it does not act on its own.
  • SOAR runs playbooks across other tools; it needs a detection source.
  • EDR lives on the endpoint and can isolate it; XDR spans endpoint, network, cloud and email.
  • UEBA compares behavior with a baseline, which suits threats that use valid credentials.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.