An enterprise security team is configuring an automated Security Orchestration, Automation, and Response (SOAR) playbook to respond to high-confidence phishing alerts containing malicious URL links. The team wants to execute rapid containment and context enrichment while preventing self-inflicted operational outages. Which of the following automated actions should be incorporated into this playbook? (Select TWO.)
- Query threat intelligence feeds via API webhooks to enrich the incident with domain reputation scores and known indicators of compromise.Cevap
- Revoke active user session tokens and trigger a forced credential reset through Identity Provider (IdP) API integration.Cevap
- CAutomatically add the primary internal corporate domain to the perimeter firewall blocklist upon initial alert ingestion.
- DElevate targeted user account permissions to Domain Administrator to allow the SOAR platform to inspect local machine logs.
Cevap
The appropriate automated response actions are querying threat intelligence feeds via API webhooks to enrich incident context and revoking active user session tokens with a forced credential reset via Identity Provider API integration.
The correct response actions include enriching alert context via threat intelligence API integrations and performing targeted identity containment by revoking active user sessions through Identity Provider APIs. These steps isolate compromised credentials and supply vital contextual data without risking self-inflicted enterprise downtime.
Adım Adım Çözüm
Anahtar Kavram
SOAR Playbook Design and Automated Incident Response Integration