ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 335 - SY0-701 discussion

Report
Export

Which of the following should a security operations center use to improve its incident response procedure?

A.
Playbooks
Answers
A.
Playbooks
B.
Frameworks
Answers
B.
Frameworks
C.
Baselines
Answers
C.
Baselines
D.
Benchmarks
Answers
D.
Benchmarks
Suggested answer: A

Explanation:

A playbook is a documented set of procedures that outlines the step-by-step response to specific types of cybersecurity incidents. Security Operations Centers (SOCs) use playbooks to improve consistency, efficiency, and accuracy during incident response. Playbooks help ensure that the correct procedures are followed based on the type of incident, ensuring swift and effective remediation.

Frameworks provide general guidelines for implementing security but are not specific enough for incident response procedures.

Baselines represent normal system behavior and are used for anomaly detection, not incident response guidance.

Benchmarks are performance standards and are not directly related to incident response.

asked 02/10/2024
ce temp2
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first