CompTIA CySA+ (CS0-003)Security OperationsMedium

A SOC integrates its SOAR platform with the organization's ITSM tool. When an employee-reported phishing email triggers the playbook, the SOAR platform automatically opens a ticket, assigns it to the on-call analyst, attaches extracted indicators, and updates the ticket status as each remediation step completes. Which SOAR capability does this scenario primarily illustrate?

  1. ACase management integration
  2. BSandbox detonation
  3. CThreat intelligence enrichment
  4. DIndicator correlation
Show answer & explanation

Correct answer: A. Case management integration

Automatically creating, assigning, and updating tickets in an ITSM system as a playbook executes is the definition of case management integration — SOAR orchestrates the workflow lifecycle of an incident record. Enrichment, sandboxing, and correlation may occur as separate playbook steps, but the described behavior centers on ticket lifecycle management.

Why the other options are wrong

  • B. Sandbox detonation analyzes attachments in an isolated environment, not described here.
  • C. Enrichment adds context (e.g., WHOIS, reputation) to indicators, not ticket workflow.
  • D. Correlation links related indicators/events, not ticket lifecycle.

SOAR Case Management

The SOAR capability that automates creation, assignment, and status tracking of incident tickets within an ITSM or case management system.

  • Reduces manual ticket handling overhead
  • Keeps ticket status synced with playbook progress
  • Distinct from enrichment, correlation, and sandboxing functions

Memory trick: SOAR files the paperwork so analysts don't have to.

More Security Operations questions