A Security Operations Center (SOC) analyst wants to standardize and automate the incident response steps for phishing alerts. The workflow needs to automatically extract suspicious URLs, query threat intelligence sources, and isolate affected endpoints without manual intervention. Which SOAR component should the analyst configure to execute this automated sequence of actions?
- A security playbookAnswer
- BA SIEM log correlation rule
- CA threat intelligence data feed
- DAn identity authentication gateway
Answer
A security playbook is the SOAR component used to execute automated, multi-step incident response workflows.
A security playbook is a automated linear or conditional script used by SOAR platforms to orchestrate incident response processes across connected systems. It allows SOC teams to automate repeated tasks such as extracting indicators, querying threat feeds, and isolating compromised hosts.
Step-by-Step Solution
Key Concept
SOAR Playbooks and Automated Response