CompTIA Security+ (SY0-701)Security OperationsMedium

A security team wants to automatically isolate an infected endpoint from the network, disable the compromised user account, and open a ticket whenever the EDR platform detects ransomware behavior, all without analyst intervention. Which capability BEST supports this requirement?

  1. AA SOAR playbook that orchestrates predefined automated response actions
  2. BA manual runbook printed for the on-call analyst
  3. CA vulnerability scanner scheduled to run weekly
  4. DA configuration management database (CMDB) update script
Show answer & explanation

Correct answer: A. A SOAR playbook that orchestrates predefined automated response actions

Security Orchestration, Automation, and Response (SOAR) platforms use playbooks to automatically execute a sequence of response actions across multiple tools when specific triggers occur, enabling fast, consistent incident response without manual steps.

Why the other options are wrong

  • B. A printed manual runbook still requires human execution, not automation.
  • C. Vulnerability scanners identify weaknesses; they do not perform incident response actions.
  • D. A CMDB update script only maintains asset records, not incident response.

SOAR Playbook

A predefined, automated workflow within a Security Orchestration, Automation, and Response platform that executes multiple response actions in sequence when triggered by an alert.

  • Orchestrates actions across multiple security tools
  • Reduces mean time to respond (MTTR)
  • Can isolate hosts, disable accounts, create tickets automatically
  • Requires integration APIs between tools

Memory trick: SOAR lets the system fly the response itself.

More Security Operations questions