CompTIA SY0-601 Practice Test 4
Question 1 / 40
As part of the lessons-learned phase, the SOC is tasked with building methods to detect if a previous incident is happening again. Which of the following would allow the security analyst to alert the SOC if an event is reoccurring?
Creating a playbook within the SOAR
Implementing rules in the NGFW
Updating the DLP hash database
Publishing a new CRL with revoked certificates
Comment (0)
Suggested answer: A
Explanation:
Creating a playbook within the Security Orchestration, Automation and Response (SOAR) tool would allow the security analyst to detect if an event is reoccurring by triggering automated actions based on the previous incident's characteristics. This can help the SOC to respond quickly and effectively to the incident. Reference: CompTIA Security+ Study Guide, Exam SY0-601, 4th Edition, Chapter 7:
Incident Response, pp. 352-354