Soru

Zorluk: KolaySecurity Automation and Orchestration (SOAR)

Place the typical steps of an automated Security Orchestration, Automation, and Response (SOAR) incident playbook in the correct operational sequence from first to last.

  1. 1Ingest the alert payload automatically from a SIEM or EDR integration.
  2. 2Enrich the alert data by querying external threat intelligence feeds for IP and domain reputation.
  3. 3Execute active containment measures, such as applying a firewall block rule or isolating the affected endpoint.
  4. 4Update the incident ticket in the ITSM platform with execution logs and notify the security analyst.

Cevap

The correct operational sequence for an automated SOAR playbook is: 1) Ingest the alert payload automatically from a SIEM or EDR integration, 2) Enrich the alert data by querying external threat intelligence feeds for IP and domain reputation, 3) Execute active containment measures, such as applying a firewall block rule or isolating the affected endpoint, and 4) Update the incident ticket in the ITSM platform with execution logs and notify the security analyst.
An automated SOAR incident response playbook follows a logical operational flow: alert ingestion occurs first upon event detection, followed immediately by automated threat intelligence enrichment. After validating indicators, the playbook executes active containment integrations (such as network blocks or host isolation), and concludes by updating the ticketing system with full execution logs.

Adım Adım Çözüm

1
Trigger workflow upon alert reception
Alert data is passed into the SOAR engine.
An automated playbook requires a triggered event payload to initiate execution.
2
Perform contextual threat enrichment
Indicators of compromise are checked against threat intelligence.
Gathering context ensures containment decisions are based on verified threat reputation.
3
Invoke automated containment integrations
Network perimeter or endpoint controls block the threat.
Containment API calls execute after conditions and enrichment checks pass.
4
Complete ticketing and analyst notification
The incident tracking system records all automated actions.
Final documentation and audit trail updates occur after containment actions finish.

Anahtar Kavram

SOAR Playbook Execution Lifecycle
Bu soruyu puanla