Soru

Zorluk: KolaySecurity Automation and Orchestration (SOAR)

A security analyst is setting up an automated Security Orchestration, Automation, and Response (SOAR) playbook to streamline initial response tasks when a suspicious email attachment is reported. Which of the following tasks are most appropriate for full automation without requiring human-in-the-loop approval? (Select TWO.)

  1. Submitting the suspicious attachment hash to external threat intelligence feeds for automated reputation scoringCevap
  2. Isolating the affected recipient workstation from the internal network using integrated endpoint protection toolsCevap
  3. C
    Disabling all active enterprise domain admin accounts upon initial alert ingestion
  4. D
    Modifying firewall policy access control rules to grant full administrative rights to the sender

Cevap

The actions appropriate for full automation are querying external threat intelligence feeds for hash reputation scoring and isolating the recipient workstation via endpoint security controls.
Automating reputation lookups with threat intelligence feeds allows rapid risk assessment without operational risk. Similarly, isolating a single workstation prevents lateral movement of suspected fileless or payload-based malware while keeping containment tightly targeted.

Adım Adım Çözüm

1
Identify non-disruptive enrichment workflows suitable for SOAR playbooks.
Automated hash reputation lookup against threat intelligence sources enriches alert telemetry safely.
Enrichment tasks are read-only and do not affect business operations.
2
Identify targeted containment controls for individual endpoint protection.
Host isolation via Endpoint Detection and Response (EDR) limits lateral threat movement.
Host isolation protects the broader network while targeting only the potentially compromised machine.

Anahtar Kavram

SOAR Playbook Automation and Enrichment
Tahmini Süre:1m 0s
Bu soruyu puanla