CompTIA CySA+ (CS0-003)Security OperationsEasy

A SOC wants to reduce mean time to respond (MTTR) for phishing reports submitted by employees. They implement a workflow where, upon a user reporting a suspicious email, the system automatically extracts the sender, URLs, and attachment hash, queries threat intelligence feeds, and quarantines the message across all mailboxes if the indicators are found malicious—all without analyst intervention. What is this capability best described as?

  1. AA SOAR playbook
  2. BA vulnerability scanner policy
  3. CAn intrusion prevention system signature
  4. DA SIEM correlation rule
Show answer & explanation

Correct answer: A. A SOAR playbook

This describes a SOAR (Security Orchestration, Automation, and Response) playbook: a predefined, automated sequence of actions (enrichment, decision, remediation) triggered by an event, executed without manual analyst steps.

Why the other options are wrong

  • B. Vulnerability scanner policies define scan scope/schedule, unrelated to phishing response automation.
  • C. IPS signatures block malicious network traffic patterns, not orchestrate email investigation/quarantine workflows.
  • D. A SIEM correlation rule detects/alerts on patterns but does not orchestrate multi-step automated remediation across mailboxes.

SOAR Playbook

A predefined, automated workflow within a Security Orchestration, Automation, and Response platform that executes a sequence of investigation and remediation actions in response to a trigger.

  • Reduces MTTR by removing manual repetitive steps
  • Combines orchestration (integrating tools) with automation (executing actions)
  • Common use cases: phishing triage, malware containment, account lockout

Memory trick: SOAR = the robot that reads, checks, and locks the door itself.

More Security Operations questions