CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is designing an automated incident response (IR) workflow for a cloud environment. The goal is to quickly isolate compromised virtual machines (VMs) and revoke their access credentials upon detection of a high-severity threat. The solution needs to integrate with various cloud provider APIs and internal security tools. Which automation approach would be MOST effective for orchestrating these complex, multi-step actions across different systems?

  1. AWriting custom shell scripts for each action.
  2. BImplementing a Security Orchestration, Automation, and Response (SOAR) platform.
  3. CManually updating firewall rules and IAM policies.
  4. DUsing a simple cron job to periodically check logs.
Show answer & explanation

Correct answer: B. Implementing a Security Orchestration, Automation, and Response (SOAR) platform.

A Security Orchestration, Automation, and Response (SOAR) platform is specifically designed to orchestrate and automate complex, multi-step incident response workflows across disparate security tools and cloud APIs. It can ingest alerts, apply playbooks, and execute automated actions like isolating VMs and revoking credentials by integrating with various systems, making it the most effective solution for the described scenario. This allows for rapid and consistent response to high-severity threats.

Why the other options are wrong

  • A. Custom shell scripts are difficult to maintain, scale, and integrate across various APIs, lacking the orchestration capabilities needed for complex IR workflows.
  • C. Manually updating rules and policies is slow, error-prone, and not scalable for rapid incident response, directly contradicting the goal of quick isolation and revocation.
  • D. A cron job can schedule tasks but lacks the event-driven, conditional logic, integration capabilities, and rich orchestration features required for comprehensive incident response automation.

SOAR Platform

A SOAR (Security Orchestration, Automation, and Response) platform is a software solution that helps organizations collect threat-related data, automate security tasks, and orchestrate incident response workflows.

  • Automates repetitive security tasks and incident response.
  • Integrates with various security tools and threat intelligence feeds.
  • Uses playbooks to standardize and accelerate response actions.
  • Improves incident handling efficiency and reduces response times.

Memory trick: SOAR Orchestrates Rapid Cloud Response

More Security Engineering questions