ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 330 - SY0-601 discussion

Report
Export

An email security vendor recently added a retroactive alert after discovering a phishing email had already been delivered to an inbox. Which of the following would be the best way for the security administrator to address this type of alert in the future?

A.
Utilize a SOAR playbook to remove the phishing message.
Answers
A.
Utilize a SOAR playbook to remove the phishing message.
B.
Manually remove the phishing emails when alerts arrive.
Answers
B.
Manually remove the phishing emails when alerts arrive.
C.
Delay all emails until the retroactive alerts are received.
Answers
C.
Delay all emails until the retroactive alerts are received.
D.
Ingest the alerts into a SIEM to correlate with delivered messages.
Answers
D.
Ingest the alerts into a SIEM to correlate with delivered messages.
Suggested answer: A

Explanation:

One possible way to address this type of alert in the future is to use a SOAR (Security Orchestration, Automation, and Response) playbook to automatically remove the phishing message from the inbox3. A SOAR playbook is a set of predefined actions that can be triggered by certain events or conditions. This can help reduce the response time and human error in dealing with phishing alerts.

asked 02/10/2024
Renier Janse van Rensburg
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first