Soru

Zorluk: OrtaSecurity Automation and Orchestration (SOAR)

An enterprise security team is configuring an automated Security Orchestration, Automation, and Response (SOAR) playbook to respond to high-confidence phishing alerts containing malicious URL links. The team wants to execute rapid containment and context enrichment while preventing self-inflicted operational outages. Which of the following automated actions should be incorporated into this playbook? (Select TWO.)

  1. Query threat intelligence feeds via API webhooks to enrich the incident with domain reputation scores and known indicators of compromise.Cevap
  2. Revoke active user session tokens and trigger a forced credential reset through Identity Provider (IdP) API integration.Cevap
  3. C
    Automatically add the primary internal corporate domain to the perimeter firewall blocklist upon initial alert ingestion.
  4. D
    Elevate targeted user account permissions to Domain Administrator to allow the SOAR platform to inspect local machine logs.

Cevap

The appropriate automated response actions are querying threat intelligence feeds via API webhooks to enrich incident context and revoking active user session tokens with a forced credential reset via Identity Provider API integration.
The correct response actions include enriching alert context via threat intelligence API integrations and performing targeted identity containment by revoking active user sessions through Identity Provider APIs. These steps isolate compromised credentials and supply vital contextual data without risking self-inflicted enterprise downtime.

Adım Adım Çözüm

1
Identify the primary goals of the automated incident response playbook.
The core goals are context enrichment and rapid, non-disruptive containment of the compromised account.
SOAR playbooks should streamline triage and mitigate active threats while maintaining operational continuity.
2
Assess threat intelligence enrichment mechanisms.
Querying external threat feeds via API webhooks retrieves domain reputation and indicators of compromise automatically.
API integrations allow the SOAR platform to gather contextual intelligence without affecting network access or infrastructure stability.
3
Evaluate containment actions for risk and efficacy.
Revoking session tokens via Identity Provider APIs isolates the specific compromised user identity, whereas adding internal domains to perimeter firewalls creates catastrophic operational outage.
Targeted API-driven identity containment neutralizes user compromise safely, whereas flawed playbook logic can take down critical services.

Anahtar Kavram

SOAR Playbook Design and Automated Incident Response Integration
Bu soruyu puanla