ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 349 - CAS-004 discussion

Report
Export

A new, online file hosting service is being offered. The service has the following security requirements:

• Threats to customer data integrity and availability should be remediated first.

• The environment should be dynamic to match increasing customer demands.

• The solution should not interfere with customers" ability to access their data at anytime.

• Security analysts should focus on high-risk items.

Which of the following would BEST satisfy the requirements?

A.
Expanding the use of IPS and NGFW devices throughout the environment
Answers
A.
Expanding the use of IPS and NGFW devices throughout the environment
B.
Increasing the number of analysts to Identify risks that need remediation
Answers
B.
Increasing the number of analysts to Identify risks that need remediation
C.
Implementing a SOAR solution to address known threats
Answers
C.
Implementing a SOAR solution to address known threats
D.
Integrating enterprise threat feeds in the existing SIEM
Answers
D.
Integrating enterprise threat feeds in the existing SIEM
Suggested answer: C

Explanation:

A SOAR (Security Orchestration, Automation, and Response) solution is a software platform that can automate the detection and response of known threats, such as ransomware, phishing, or denial-ofservice

attacks. A SOAR solution can also integrate with other security tools, such as IPS, NGFW,

SIEM, and threat feeds, to provide a comprehensive and dynamic security posture. A SOAR solution would best satisfy the requirements of the online file hosting service, because it would:

Remediate threats to customer data integrity and availability first, by automatically applying predefined actions or workflows based on the severity and type of the threat.

Allow the environment to be dynamic to match increasing customer demands, by scaling up or down the security resources and processes as needed.

Not interfere with customers’ ability to access their data at anytime, by minimizing the human intervention and downtime required for threat response.

Enable security analysts to focus on high-risk items, by reducing the manual tasks and alert fatigue associated with threat detection and response.

Reference: CASP+ (Plus) CompTIA Advanced Security Practitioner Certification …

asked 02/10/2024
Farid Tannouch
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first