During a high-volume credential stuffing campaign targeted at an enterprise web portal, an automated Security Orchestration, Automation, and Response (SOAR) playbook is triggered upon detecting repeated failed authentication alerts. To rapidly mitigate the active attack while minimizing the risk of self-inflicted service outages on critical infrastructure, which of the following actions should be configured as the initial automated response step in the playbook?
- Dynamically apply a temporary perimeter firewall drop rule for the external source IP addresses associated with the failed login requests while querying threat intelligence feeds for enrichment.Cevap
- BAutomatically disable the network interface of the primary active directory authentication server hosting the targeted user accounts.
- CAppend a detective event tag to the central SIEM correlation engine without triggering network isolation or account state changes.
- DModify the role-based access control authorization policies to revoke resource permissions for the targeted end-user identity accounts.
Cevap
Dynamically applying a temporary perimeter firewall drop rule for the external source IP addresses associated with the failed login requests while querying threat intelligence feeds for enrichment.
The correct response dynamically blocks the external source IP addresses carrying out the attack at the perimeter while enriching alert data via threat intelligence. This encapsulates the core purpose of Security Automation and Orchestration (SOAR)—executing rapid, low-risk containment steps automatically while preserving system availability.
Adım Adım Çözüm
Anahtar Kavram
Security Automation Playbook Design and Risk-Aware Containment