A security analyst is setting up an automated Security Orchestration, Automation, and Response (SOAR) playbook to streamline initial response tasks when a suspicious email attachment is reported. Which of the following tasks are most appropriate for full automation without requiring human-in-the-loop approval? (Select TWO.)
- Submitting the suspicious attachment hash to external threat intelligence feeds for automated reputation scoringCevap
- Isolating the affected recipient workstation from the internal network using integrated endpoint protection toolsCevap
- CDisabling all active enterprise domain admin accounts upon initial alert ingestion
- DModifying firewall policy access control rules to grant full administrative rights to the sender
Cevap
The actions appropriate for full automation are querying external threat intelligence feeds for hash reputation scoring and isolating the recipient workstation via endpoint security controls.
Automating reputation lookups with threat intelligence feeds allows rapid risk assessment without operational risk. Similarly, isolating a single workstation prevents lateral movement of suspected fileless or payload-based malware while keeping containment tightly targeted.
Adım Adım Çözüm
Anahtar Kavram
SOAR Playbook Automation and Enrichment
Tahmini Süre:1m 0s