CompTIA Security+ (SY0-701)Security OperationsHard
A security engineer is configuring a network device to block traffic from known malicious IP addresses and domains. This device automatically updates its block lists based on feeds from various threat intelligence sources and can also coordinate responses with other security tools. Which type of security tool is being described?
- ASecurity Information and Event Management (SIEM)
- BIntrusion Prevention System (IPS)
- CSecurity Orchestration, Automation, and Response (SOAR)
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: C. Security Orchestration, Automation, and Response (SOAR)
While an IPS can block traffic, the key differentiator here is the ability to 'coordinate responses with other security tools' and 'automatically update its block lists based on feeds.' This orchestration and automation capability is the hallmark of a SOAR platform, which integrates various security tools and workflows.
Why the other options are wrong
- A. A SIEM aggregates and correlates logs but primarily for monitoring and alerting, not for automated orchestration of responses.
- B. An IPS blocks traffic based on signatures or behavioral rules but typically does not orchestrate responses with other disparate security tools in a broader sense.
- D. DLP focuses on preventing sensitive data exfiltration, which is unrelated to blocking malicious IPs and orchestrating responses.
Security Orchestration, Automation, and Response (SOAR)
A platform that integrates security tools, automates security tasks, and orchestrates incident response workflows to improve efficiency and speed.
- Connects disparate security solutions.
- Automates repetitive tasks, reducing manual effort.
- Enables faster and more consistent incident response.
Memory trick: SOAR is the 'Orchestra Conductor' for security tools.