ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 121 - SY0-601 discussion

Report
Export

As part of the lessons-learned phase, the SOC is tasked with building methods to detect if a previous incident is happening again. Which of the following would allow the security analyst to alert the SOC if an event is reoccurring?

A.
Creating a playbook within the SOAR
Answers
A.
Creating a playbook within the SOAR
B.
Implementing rules in the NGFW
Answers
B.
Implementing rules in the NGFW
C.
Updating the DLP hash database
Answers
C.
Updating the DLP hash database
D.
Publishing a new CRL with revoked certificates
Answers
D.
Publishing a new CRL with revoked certificates
Suggested answer: A

Explanation:

Creating a playbook within the Security Orchestration, Automation and Response (SOAR) tool would allow the security analyst to detect if an event is reoccurring by triggering automated actions based on the previous incident's characteristics. This can help the SOC to respond quickly and effectively to the incident. Reference: CompTIA Security+ Study Guide, Exam SY0-601, 4th Edition, Chapter 7:

Incident Response, pp. 352-354

asked 02/10/2024
Solanki Narendra
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first