CompTIA Security+ (SY0-701)Security OperationsMedium
A security team wants to automatically isolate an infected endpoint from the network, disable the compromised user account, and open a ticket whenever the EDR platform detects ransomware behavior, all without analyst intervention. Which capability BEST supports this requirement?
- AA SOAR playbook that orchestrates predefined automated response actions
- BA manual runbook printed for the on-call analyst
- CA vulnerability scanner scheduled to run weekly
- DA configuration management database (CMDB) update script
Show answer & explanationAnswer & explanation
Correct answer: A. A SOAR playbook that orchestrates predefined automated response actions
Security Orchestration, Automation, and Response (SOAR) platforms use playbooks to automatically execute a sequence of response actions across multiple tools when specific triggers occur, enabling fast, consistent incident response without manual steps.
Why the other options are wrong
- B. A printed manual runbook still requires human execution, not automation.
- C. Vulnerability scanners identify weaknesses; they do not perform incident response actions.
- D. A CMDB update script only maintains asset records, not incident response.
SOAR Playbook
A predefined, automated workflow within a Security Orchestration, Automation, and Response platform that executes multiple response actions in sequence when triggered by an alert.
- Orchestrates actions across multiple security tools
- Reduces mean time to respond (MTTR)
- Can isolate hosts, disable accounts, create tickets automatically
- Requires integration APIs between tools
Memory trick: SOAR lets the system fly the response itself.