Soru

Zorluk: Çok zorSecurity Automation and Orchestration (SOAR)

An organization is updating a SOAR playbook to mitigate compromised API access keys linked to high-availability microservices. To prevent accidental operational outages on mission-critical services while maintaining rapid incident containment and enrichment, which TWO of the following playbook configurations should be implemented?

  1. Incorporate a human-in-the-loop manual approval step before executing automated account or access suspension against critical production infrastructure.Cevap
  2. B
    Configure the playbook to automatically trigger full network segment isolation on core identity servers immediately upon receiving a single unverified anomaly alert.
  3. Execute temporary API session token revocation while simultaneously querying threat intelligence connectors for context enrichment.Cevap
  4. D
    Reclassify automated SOAR containment scripts as detective administrative controls to bypass technical authorization checks during execution.

Cevap

The playbook should require human-in-the-loop approval before suspending critical production assets and perform targeted API session token revocation paired with threat intelligence enrichment.
Integrating a human-in-the-loop authorization gate before modifying critical production assets prevents automated outages. Concurrently, revoking active API session tokens and gathering threat intelligence achieves rapid, focused containment while preserving surrounding microservice availability.

Adım Adım Çözüm

1
Evaluate the risk of automated containment actions against mission-critical infrastructure.
Unconditional automated isolation of critical production services presents an unacceptably high risk of self-inflicted downtime.
Human-in-the-loop (HITL) approval gates ensure human authorization before destructive containment steps execute against core services.
2
Select targeted containment mechanisms with low operational blast radius.
Revoking specific API session tokens disrupts adversary access without impacting underlying host OS or service availability.
Token revocation neutralizes compromised credential misuse quickly while automated threat intelligence feeds provide context to SOC analysts.

Anahtar Kavram

SOAR Playbook Logic, Operational Risk Mitigation, and Targeted Response
Tahmini Süre:2m 0s
Bu soruyu puanla