ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 508 - CAS-004 discussion

Report
Export

An analyst determined that the current process for manually handling phishing attacks within the company is ineffective. The analyst is developing a new process to ensure phishing attempts are handled internally in an appropriate and timely manner. One of the analyst's requirements is that a blocklist be updated automatically when phishing attempts are identified. Which of the following would help satisfy this requirement?

A.
SOAR
Answers
A.
SOAR
B.
MSSP
Answers
B.
MSSP
C.
Containerization
Answers
C.
Containerization
D.
Virtualization
Answers
D.
Virtualization
E.
MDR deployment
Answers
E.
MDR deployment
Suggested answer: A

Explanation:

To automate the process of handling phishing attempts and updating blocklists, the best solution is to implement SOAR (Security Orchestration, Automation, and Response). SOAR platforms allow organizations to define automated workflows for responding to security incidents, such as phishing attacks. In this case, SOAR can automate the identification of phishing attempts and update blocklists in real-time, improving response time and consistency. MSSP (Managed Security Service Provider) and MDR (Managed Detection and Response) are outsourced services that do not directly address the need for automation, and containerization and virtualization are unrelated to incident handling. CASP+ emphasizes the value of automation in streamlining security operations and improving response times to threats.

CASP+ CAS-004 Exam Objectives: Domain 2.0 -- Enterprise Security Operations (Automation, SOAR)

CompTIA CASP+ Study Guide: Security Automation and Incident Response with SOAR

asked 02/10/2024
Dominique Dusabe
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first