A security operations team is configuring playbooks in a Security Orchestration, Automation, and Response (SOAR) platform to streamline incident triage and containment. Which of the following operational tasks are typically automated using SOAR playbooks? (Select TWO.)
- Enriching incoming alert data by querying threat intelligence feeds via APIsCevap
- Executing API calls to perimeter firewalls to block malicious IP addressesCevap
- CEstablishing executive business risk tolerance thresholds during an enterprise breach
- DRedesigning secure network architecture and VLAN segment boundaries
Cevap
Enriching incoming alert data with threat intelligence feeds and automatically issuing API commands to firewalls for IP containment are standard SOAR playbook functions.
SOAR platforms excel at orchestrating tools and automating repetitive incident response workflows. Querying external threat intelligence services via API to enrich SIEM alerts accelerates triage without human intervention. Similarly, executing pre-approved containment commands—such as calling a firewall API to block a malicious IP address—dramatically reduces mean time to respond (MTTR).
Adım Adım Çözüm
Anahtar Kavram
Security Automation and Orchestration (SOAR) Playbook Capabilities