A Security Operations Center (SOC) team is designing an automated Security Orchestration, Automation, and Response (SOAR) playbook to mitigate high-volume brute-force authentication attacks against a web portal. The security team must ensure rapid response while avoiding operational self-denial of service (DoS) against critical enterprise infrastructure or legitimate traffic. Which of the following playbook design strategies best achieves automated containment while minimizing operational risk?
- Automatically append external source IP addresses exceeding the failed login threshold to a temporary perimeter firewall blocklist while excluding trusted enterprise IP ranges.Cevap
- BAutomatically isolate the web portal's primary database cluster from the network immediately upon detecting an authentication failure threshold breach.
- CConfigure the playbook to automatically revoke administrative authorization roles across the directory service whenever a external user fails login authentication.
- DReclassify all automated IP block actions as detective monitoring controls so that firewall block rules do not disrupt active sessions.
Cevap
Automatically appending external source IP addresses exceeding the failed login threshold to a temporary perimeter firewall blocklist while excluding trusted enterprise IP ranges best balances rapid response with operational safety.
The option advocating temporary firewall blocklisting of external source IPs with trusted range exclusions represents effective SOAR playbook design. SOAR automation speeds up response times during brute-force attacks, while inclusion of temporary blocks and whitelist logic ensures operational continuity and guards against self-inflicted outages.
Adım Adım Çözüm
Anahtar Kavram
SOAR Playbook Containment Logic and Risk Mitigation
Tahmini Süre:1m 30s