exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 69 discussion

Actual exam question from CompTIA's SY0-601
Question #: 69
Topic #: 1
[All SY0-601 Questions]

The SOC for a large MSSP is meeting to discuss the lessons learned from a recent incident that took much too long to resolve. This type of incident has become more common in recent weeks and is consuming large amounts of the analysts' time due to manual tasks being performed. Which of the following solutions should the SOC consider to BEST improve its response time?

  • A. Configure a NIDS appliance using a Switched Port Analyzer.
  • B. Collect OSINT and catalog the artifacts in a central repository.
  • C. Implement a SOAR with customizable playbooks.
  • D. Install a SIEM with community-driven threat intelligence.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
varun0
Highly Voted 2 years, 7 months ago
Selected Answer: C
SOAR allows for automation of IR
upvoted 13 times
...
Tjank
Highly Voted 2 years, 7 months ago
Selected Answer: C
SOAR (Security Orchestration, Automation, and Response) Can use either playbook or runbook. It assists in collecting threat related data from a range of sources and automate responses to low level threats. (frees up some of the CSIRT time)
upvoted 8 times
...
bolajiambex
Most Recent 1 year, 7 months ago
SOAR is correct
upvoted 2 times
...
Kraken84
1 year, 8 months ago
.."large amounts of the analysts' time due to manual tasks being performed" In need of Automation?
upvoted 2 times
...
Protract8593
1 year, 9 months ago
Selected Answer: C
SOC (Security Operations Center) can improve its incident response time and efficiency by implementing a SOAR (Security Orchestration, Automation, and Response) platform with customizable playbooks. SOAR platforms help automate and streamline various security tasks and processes, allowing analysts to respond to incidents more quickly and effectively. By using customizable playbooks, the SOC can define automated workflows tailored to their specific incident response needs, reducing manual efforts and improving overall response time to security incidents.
upvoted 3 times
...
ApplebeesWaiter1122
1 year, 10 months ago
Selected Answer: C
Implementing a SOAR with customizable playbooks would be the best solution to improve the SOC's response time in this scenario. SOAR platforms are designed to streamline and automate incident response processes, allowing security analysts to respond more efficiently to security incidents. By creating customizable playbooks, the SOC can define predefined response actions and automate the execution of common and repetitive tasks. This reduces the reliance on manual processes and enables faster response times. The playbooks can include automated investigation, enrichment of data with OSINT (Open Source Intelligence), and execution of response actions based on predefined rules and logic.
upvoted 2 times
...
KingDrew
2 years, 3 months ago
Selected Answer: C
SOAR is automated, and includes security orchestration and response to help resolve security issues more efficiently and timely.
upvoted 1 times
...
Jossie_C
2 years, 5 months ago
Selected Answer: C
Sounds like football but ok
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago