Soru

Zorluk: OrtaSecurity Automation and Orchestration (SOAR)

A Security Operations Center (SOC) team is designing an automated Security Orchestration, Automation, and Response (SOAR) playbook to mitigate high-volume brute-force authentication attacks against a web portal. The security team must ensure rapid response while avoiding operational self-denial of service (DoS) against critical enterprise infrastructure or legitimate traffic. Which of the following playbook design strategies best achieves automated containment while minimizing operational risk?

  1. Automatically append external source IP addresses exceeding the failed login threshold to a temporary perimeter firewall blocklist while excluding trusted enterprise IP ranges.Cevap
  2. B
    Automatically isolate the web portal's primary database cluster from the network immediately upon detecting an authentication failure threshold breach.
  3. C
    Configure the playbook to automatically revoke administrative authorization roles across the directory service whenever a external user fails login authentication.
  4. D
    Reclassify all automated IP block actions as detective monitoring controls so that firewall block rules do not disrupt active sessions.

Cevap

Automatically appending external source IP addresses exceeding the failed login threshold to a temporary perimeter firewall blocklist while excluding trusted enterprise IP ranges best balances rapid response with operational safety.
The option advocating temporary firewall blocklisting of external source IPs with trusted range exclusions represents effective SOAR playbook design. SOAR automation speeds up response times during brute-force attacks, while inclusion of temporary blocks and whitelist logic ensures operational continuity and guards against self-inflicted outages.

Adım Adım Çözüm

1
Analyze the threat vector and operational requirements.
Identified high-volume brute-force attacks needing automated containment that stops malicious traffic without disrupting legitimate enterprise services.
SOAR playbooks must balance automated speed with risk management to avoid unexpected outages of critical business systems.
2
Evaluate containment actions against operational safety controls.
Enforcing temporary IP blocks on malicious external sources while incorporating allowlists for internal/trusted infrastructure prevents self-inflicted denial of service.
Safeguarding critical assets and enterprise egress ranges ensures that automated playbooks do not inadvertently isolate core infrastructure.

Anahtar Kavram

SOAR Playbook Containment Logic and Risk Mitigation
Tahmini Süre:1m 30s
Bu soruyu puanla