ExamGecko
Home / CompTIA / SY0-601 / Practice Test 4
Ask Question

CompTIA SY0-601 Practice Test 4

00:00:00
Show Answer
Report Issue   Restart test

Question 1 / 40

As part of the lessons-learned phase, the SOC is tasked with building methods to detect if a previous incident is happening again. Which of the following would allow the security analyst to alert the SOC if an event is reoccurring?

Creating a playbook within the SOAR
Creating a playbook within the SOAR
Implementing rules in the NGFW
Implementing rules in the NGFW
Updating the DLP hash database
Updating the DLP hash database
Publishing a new CRL with revoked certificates
Publishing a new CRL with revoked certificates
Comment (0)
Suggested answer: A
Explanation:

Creating a playbook within the Security Orchestration, Automation and Response (SOAR) tool would allow the security analyst to detect if an event is reoccurring by triggering automated actions based on the previous incident's characteristics. This can help the SOC to respond quickly and effectively to the incident. Reference: CompTIA Security+ Study Guide, Exam SY0-601, 4th Edition, Chapter 7:

Incident Response, pp. 352-354

asked 02/10/2024
Solanki Narendra
36 questions