Soru

Zorluk: KolaySecurity Automation and Orchestration (SOAR)

A security operations team is configuring playbooks in a Security Orchestration, Automation, and Response (SOAR) platform to streamline incident triage and containment. Which of the following operational tasks are typically automated using SOAR playbooks? (Select TWO.)

  1. Enriching incoming alert data by querying threat intelligence feeds via APIsCevap
  2. Executing API calls to perimeter firewalls to block malicious IP addressesCevap
  3. C
    Establishing executive business risk tolerance thresholds during an enterprise breach
  4. D
    Redesigning secure network architecture and VLAN segment boundaries

Cevap

Enriching incoming alert data with threat intelligence feeds and automatically issuing API commands to firewalls for IP containment are standard SOAR playbook functions.
SOAR platforms excel at orchestrating tools and automating repetitive incident response workflows. Querying external threat intelligence services via API to enrich SIEM alerts accelerates triage without human intervention. Similarly, executing pre-approved containment commands—such as calling a firewall API to block a malicious IP address—dramatically reduces mean time to respond (MTTR).

Adım Adım Çözüm

1
Identify the primary purpose of SOAR playbooks in security operations
SOAR playbooks automate repeatable triage, enrichment, and containment actions to reduce response times.
Automation focuses on programmatic tasks executed through integrations and APIs.
2
Evaluate each operational task against automated playbook capabilities
API queries to threat intelligence sources and automated API calls to firewalls to block IP addresses represent programmatic automation.
Strategic governance and structural network redesign require human decision-making and planning.

Anahtar Kavram

Security Automation and Orchestration (SOAR) Playbook Capabilities
Bu soruyu puanla