What is the simplest way to separate the five tools?
The simplest way is to match each tool to its main action, then check where it operates. Expanding every acronym helps less than recognising what the question asks the analyst to do.
Scroll sideways to see every column.
| Tool | Full name | Remember the job | Scenario clue |
|---|---|---|---|
| IDS | Intrusion detection system | Notice and alert | Detect suspicious traffic |
| IPS | Intrusion prevention system | Inspect and stop | Block an attack in the traffic path |
| SIEM | Security information and event management | Collect and connect | Correlate identity, firewall and server logs |
| SOAR | Security orchestration, automation and response | Run a workflow | Enrich an alert, open a ticket and trigger containment |
| EDR | Endpoint detection and response | Investigate the device | Trace processes or isolate a laptop |
How do IDS and IPS differ?
IDS focuses on detection and alerts; IPS adds the ability to prevent detected activity. A common network IDS watches a copy of traffic. A network IPS commonly sits inline, where traffic passes through it and can be blocked. NIST SP 800-94 covers intrusion detection and prevention approaches.
Placement affects the trade-off. A false alert from a passive sensor costs investigation time. A false positive from an inline prevention device can interrupt legitimate traffic. Both need sensible rules and tuning.
Don’t turn the memory aid into a claim that every IDS is passive or that every IPS catches every attack. Host-based designs exist too. Read whether the question needs an alert, a block, or a control on a particular system.
Tool placement makes more sense when you trace the firewall, proxy and segmented network paths that carry the traffic.
A network alert may name a service port; use the protocol’s purpose and transport to interpret that clue.
How do SIEM and SOAR differ?
SIEM brings security events together for analysis, while SOAR coordinates the steps used to investigate and respond. A SIEM might link a suspicious login, a firewall connection and a server event into one incident. A SOAR workflow could then enrich an address, request approval to disable an account, and create a case record.
The boundary can overlap in commercial tools. Microsoft’s SIEM and XDR documentation shows correlation, hunting and automation capabilities working together. The exam distinction is the requested function, not which vendor sells it.
Automation also needs safeguards. Automatically disabling every account with a failed login would cause avoidable outages. A useful workflow has conditions, permissions and approval steps where the action could disrupt work.
Login and access events are easier to interpret when you separate authentication, authorization and accounting.
A pattern of failures across many accounts can support an investigation into password spraying rather than credential stuffing.
What makes EDR different from a network sensor?
EDR uses endpoint evidence such as process activity and device events, giving analysts a view inside the machine. A network sensor might see a connection to a suspicious address. EDR can help show which process made it, what launched that process and what happened next.
Response actions can include isolating the endpoint from the network while preserving an investigation channel. Available actions depend on the product and permissions. A suspicious IP alone doesn’t tell you every step that ran on a laptop.
EDR isn’t simply another name for a firewall. Firewalls control allowed traffic; EDR investigates and responds to activity on devices. Both can help in the same incident.
A file digest can help compare an observed file with a known value; remember what hashing can and cannot establish.
For encrypted network sessions, distinguish key establishment from traffic encryption before assuming a sensor can inspect readable content.
How would these tools work during one incident?
The tools would contribute different evidence and actions during the same incident. Consider an original example: an employee opens a malicious attachment, a script runs, and the laptop contacts an external server.
EDR records the script and its parent process. A network IDS notices suspicious traffic, or an IPS blocks it if its policy matches. The SIEM connects the device event with the employee’s login and network logs. A SOAR playbook gathers context, creates a ticket and asks an analyst to approve isolation.
This sequence illustrates their jobs; it isn’t a required order. An endpoint might be isolated before a SIEM correlation finishes, and one product can cover more than one role.
Containment decisions can affect service recovery, so keep RTO, RPO and observed recovery time distinct.
- 01Endpoint evidenceEDR traces the script and process
- 02Connected evidenceSIEM links device, login and network events
- 03Response workflowSOAR coordinates approved actions
How do I practise choosing the best tool?
Practise by underlining the task verb and the evidence location before choosing a tool. Correlate across systems points to SIEM; carry out a repeatable response points to SOAR; trace a process tree points to EDR.
For broader task choices, compare scanning, penetration testing, threat hunting and risk assessment.
Use the task verb and evidence location when working through a performance-based question, too.