ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 359 - CS0-003 discussion

Report
Export

Which of the following is most appropriate to use with SOAR when the security team would like to automate actions across different vendor platforms?

A.

STIX/TAXII

Answers
A.

STIX/TAXII

B.

APIs

Answers
B.

APIs

C.

Data enrichment

Answers
C.

Data enrichment

D.

Threat feed

Answers
D.

Threat feed

Suggested answer: B

Explanation:

APIs (Application Programming Interfaces) enable integration and automation across different vendor platforms within a SOAR (Security Orchestration, Automation, and Response) solution. They allow security tools to communicate and execute automated actions, making them essential for orchestrating responses across diverse systems and platforms. While STIX/TAXII provides standards for threat information sharing, and data enrichment enhances context, APIs are the primary means of enabling cross-platform automation, as recommended in CompTIA CySA+ materials on SOAR operations.

asked 17/10/2024
Paul Schwarz
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first